Key Takeaways
- Trezor says Shipmonk exposed data for about 13,689 recent customers.
- Trezor devices remain secure, but phishing risks rose after the Aug. 10 breach.
- Trezor targets Anonymous Delivery for the EU by September 2026.
According to the company’s security update, the affected customers received orders in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal during the 90 days before Aug. 8, Trezor wrote. The hardware wallet maker said Shipmonk notified it of unauthorized access to systems holding customer data on Aug. 10.
Trezor said 11,742 customers had their full names, email addresses, phone numbers, and shipping addresses exposed. Another 1,947 had partial information exposed: names, cities, and email addresses.
A hardware wallet is a physical device designed to keep the private credentials used to control cryptocurrency offline. Those credentials, often called private keys, were not exposed in this incident. “All affected customers have been contacted separately by email. Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts,” Trezor explained on X.
The Immediate Risk Is Impersonation
The more immediate concern is phishing, a fraud tactic in which criminals pose as trusted companies, banks, or other services to trick people into handing over sensitive information.
“Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor,” the company said in its customer notice.
That risk is especially serious for hardware wallet owners because thieves may try to obtain a wallet backup, also known as a recovery phrase. A recovery phrase can restore access to a crypto wallet, meaning anyone who obtains it may be able to take the funds inside.
Trezor urged customers never to enter a wallet backup on a website or share it with anyone. It also advised people to treat messages seeking urgent action or personal information with suspicion and verify communications through official Trezor channels.
A Shipping Partner Held the Data
Shipmonk is a logistics provider that stores products and sends orders to buyers. Trezor said such a partner needs basic delivery information, including a recipient’s name, address, phone number, and email address.
Trezor emphasized that its own systems, products, and services were not compromised. “Trezor devices remain entirely safe and secure,” the company said, adding that normal operations continue.
The company said its 90-day retention policy limited the breach. Trezor requires fulfillment partners to delete or anonymize customer order data 90 days after delivery, once the period needed for delivery, returns, refunds, and replacements has passed.
“The one real impact is that affected customers may see more phishing attempts by email, phone, or post,” Trezor disclosed. It said affected customers were contacted directly from [email protected] and that people who did not receive that notice were not affected.
Hardware Wallet Industry Has Seen This Before
The incident is not the first customer-data breach tied to a hardware wallet maker. Ledger, another major manufacturer, suffered a breach involving its e-commerce and marketing database in 2020.
That incident exposed roughly 1 million email addresses and, later, about 272,000 more detailed customer records, including names, postal addresses, phone numbers, and ordered products.
The Ledger episode showed why personal information linked to crypto ownership can be valuable to criminals even when wallet technology itself remains secure. It can help scammers craft believable messages aimed at a known customer. Trezor explained on Thursday that it is working on a more private shipping method.
“We are currently working on an Anonymous Delivery option, which we aim to have ready by September for the EU and by the end of the year for the US. This gives you a safer way to order hardware wallets without linking the purchase to your home address or real-world identity.”
Trezor further disclosed that Shipmonk has secured and strengthened the affected systems while the investigation continues. Customers should watch for further updates, and Trezor plans to introduce Anonymous Delivery in the European Union by September and in the United States by the end of 2026.
