A breach at Trezor’s fulfillment partner leaked customer addresses, raising both phishing and physical security risk.

Original Image Credits: Ira Lichi / Shutterstock.com
Posted August 14, 2026 at 6:35 am EST.
Hardware wallet maker Trezor said a data breach at ShipMonk, the third-party fulfillment provider that stores and ships its products in several markets, exposed personal information belonging to 13,689 customers. Trezor said its own systems were not compromised and that devices, private keys and wallet backups remain secure.
ShipMonk informed Trezor on Monday, Aug. 10 that an unauthorized actor had accessed systems holding customer order data, and Trezor published a disclosure Thursday. 11,742 customers had full exposure covering name, phone number, email address and shipping address. Another estimated 1,947 had name, city and email exposed. Affected orders received between May 10 and Aug. 8 across the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal, Trezor said every affected customer was emailed directly and that anyone who did not receive a notice was not caught in the breach.
This story is an excerpt from the Unchained Daily newsletter.
Subscribe here to get these updates in your email for free
Phishing is the obvious follow-on risk, and Trezor warned that exposed customers should expect more sophisticated attempts by attackers impersonating Trezor, banks or exchanges.
But the incident also comes against a backdrop of rising physical attacks on crypto holders. Chainalysis data shows more than $30 million was stolen in violent crypto attacks during the first half of 2026, putting the year on pace to exceed 2025’s full-year total of $58 million. Unchained has previously covered how holders can reduce physical risk after the kidnapping of a Ledger co-founder in France.
Rival Ledger has been through both versions of this. A 2020 breach exposed data on more than 270,000 customers, and names, emails, phone numbers and in some cases home addresses were later posted to a hacking forum, producing years of phishing calls and physical scam letters demanding seed phrases. In January, Ledger customers were notified of another exposure through e-commerce provider Global-e.
Trezor said the scale of the incident was limited by a 90-day retention policy that it also requires of fulfillment partners, meaning older order data had already been deleted or anonymized. The company said it is the first breach since Trezor’s 2013 founding to expose customer phone numbers and shipping addresses. Trezor also pointed to an Anonymous Delivery option using locker pickup, neutral packaging and automatic deletion of shipping identifiers, which it aims to launch in the EU by September 2026 and in the U.S. by year-end.
Related Listen: Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money
AI-assisted content: This article was produced with the assistance of AI tools and was reviewed, edited, and fact-checked by a member of the Unchained editorial team before publication.
Tech,data breach,hardware wallets,ShipMonk,trezor,yahoodata breach,hardware wallets,ShipMonk,trezor,yahoo#Trezor #ShipMonk #Breach #Exposed #Names #Phone #Numbers #Home #Addresses #Customers1786705954

