Published: August 13, 2026
Trezor has disclosed a customer-data breach involving ShipMonk, one of its third-party shipping and fulfillment providers.
The most important fact comes first:
Trezor says its own systems were not compromised. Trezor hardware wallets, private keys, and wallet backups were not exposed.
The concerning part is that attackers obtained real contact and shipping information tied to thousands of Trezor customers: information that can make those customers significantly more convincing targets for crypto phishing and social-engineering attacks.
Trezor reports that approximately 13,689 customers are affected:
- 11,742 with full exposure: name, email, phone number, and shipping address
- 1,947 with partial exposure: name, city, and email
๐จ What Happened?
On August 10, 2026, ShipMonk informed Trezor that an unauthorized party had accessed systems containing customer order data.
ShipMonk is the logistics and fulfillment partner Trezor uses to store products and ship orders. Naturally, that means it held information necessary to fulfill those orders, including names, addresses, phone numbers, and email addresses.
The affected customers were in:
๐บ๐ธ United States ยท ๐ฌ๐ง United Kingdom ยท ๐ธ๐ช Sweden ยท ๐จ๐ด Colombia ยท ๐ง๐ท Brazil ยท ๐ฎ๐น Italy ยท ๐ต๐น Portugal
The affected data was limited to orders received within the 90 days before August 8, 2026.
Trezor attributes that limitation to its 90-day data-retention policy, which it says also applies to its fulfillment partners.ย That policy may have significantly reduced the amount of historical customer information available to the attacker.
๐ What Data Was Exposed?
Customer Information Exposure:
- Full exposure 11,742 Name, email, phone number, shipping address
- Partial exposure 1,947 Name, city, email
- Total 13,689 Customer/order information
What Trezor says was not compromised:
- โ Wallet private keys
- โ Wallet backups / seed phrases
- โ Trezor devices
- โ Trezor's core systems
That information is critical, and apparently, the breach occurred at a third-party fulfillment provider, not inside Trezor's wallet infrastructure.
๐ฏ Why Is This Still Serious?
For a typical e-commerce customer, having a name, phone number, email address, and physical address exposed is already a significant privacy problem.
For a confirmed hardware-wallet buyer, the information has an additional dimension:
It identifies someone as a customer of a cryptocurrency hardware-wallet company.
An attacker potentially has:
WHO โ WHERE โ PHONE โ EMAIL โ HARDWARE-WALLET CUSTOMER
That's valuable intelligence for a social-engineering campaign.
Consider the type of attack this information could enable.
This is an illustrative scenario, not a report of an actual attack.
You receive an email using your real name.ย It references your legitimate Trezor purchase.ย It contains details about your order.ย It claims that your device requires an "urgent security update." A few minutes later, someone calls claiming to be Trezor Support.
- They already know your name.
- They know you purchased a Trezor.
- They may know where you live.
- The interaction feels legitimate.
Then comes the real attack:
"For security verification, please enter your wallet backup."
๐ฅ The Rule That Doesn't Change
Trezor will never need your wallet backup.
Your seed phrase should never be:
- Entered into a website
- Typed into an email or text message
- Given to "support"
- Entered because someone called you
- Sent through a messaging app
- Shared with anyone claiming to be a Trezor representative
Anyone asking for your seed phrase is attempting to obtain control of your wallet.
The breach doesn't change this rule.
It makes following it even more important.
๐ง The Attack Doesn't Need to Break the Cryptography
This is perhaps the most important lesson from the incident.ย
Hardware-wallet security is designed around keeping the private key under the user's control.ย An attacker doesn't necessarily need to defeat the cryptography.ย They can attack the human being holding the wallet.
The potential attack chain looks like this:
Purchase data leaked
โ
Customer identified as a hardware-wallet owner
โ
Personalized phishing sent
โ
Trust and urgency established
โ
Victim voluntarily provides sensitive information
โ
Wallet potentially compromised
This is fundamentally a social-engineering problem, not a cryptographic problem. And that's an important distinction.
The cryptography can work perfectly while the user is manipulated into defeating their own security.
๐ง How Do You Know If You're Affected?
Trezor says affected customers were contacted directly by email.ย The company states that customers who did not receive its security-incident notification were not affected by this particular breach. But there's an important caveat:
Don't trust an email simply because it appears to come from Trezor.
If you receive a breach notification:
-
Don't click links in the email.
-
Open your browser independently.
-
Navigate directly to Trezor's official website.
-
Locate the security announcement yourself.
-
Contact Trezor through its official support channel if you still have questions.
The principle is simple:
Verify through a channel you control, not through a channel the message provides.
๐ก๏ธ What Affected Customers Should Do
1. Expect more sophisticated phishing
Trezor specifically warns that affected customers could see increased phishing attempts through:
- Phone calls
- SMS
- Physical mail
Treat unexpected cryptocurrency-related communications as potentially malicious until independently verified.
2. Never surrender your seed phrase
This is non-negotiable.
If someone claiming to be "Trezor Support" asks for it:
End the conversation.
3. Don't panic-move your cryptocurrency
Trezor says private keys and wallet backups were not affected.
There is therefore no indication from this breach alone that customers need to migrate their wallets.
Rushed transactions made in response to a frightening email or phone call can create additional risks.
Don't let an attacker manufacture urgency.
4. Harden your email account
Your email account can become the next attack surface.
Consider:
- Strong, unique password
- MFA
- Hardware security key where supported
- Review of account-recovery settings
- Review of active sessions
- Review of email forwarding rules
- Removal of unfamiliar recovery addresses or devices
5. Watch for phone-based social engineering
Full-exposure customers had phone numbers included in the compromised data.
A caller may already know information about you.
That doesn't make the caller legitimate.
Never authenticate a caller using information the caller already possesses.
Hang up.
Find the organization's official contact information independently.
Call back yourself.
๐ Why the 90-Day Policy Matters
One of the most interesting aspects of this incident is Trezor's data-retention policy.
Trezor says it deletes or anonymizes order data 90 days after delivery, after the period needed for delivery, returns, refunds, and replacements has passed.ย That means older customer information was reportedly no longer present in the affected fulfillment systems.
The result?ย A smaller potential blast radius.
Data that isn't retained cannot be stolen later.
Data minimization is sometimes treated as a privacy philosophy.ย This incident demonstrates the security side of the equation:
Less retained data = less data available to attackers.
The 90-day policy did not prevent the breach, but according to Trezor's disclosure, it appears to have limited how far back the exposure could reach.
๐ The Bigger Privacy Problem
There's a broader lesson here that extends beyond Trezor.
Buying a hardware wallet creates an unusual privacy footprint.
A company may know:
- Your name
- Your physical address
- Your phone number
- Your email address
- That you purchased a cryptocurrency hardware wallet
That's considerably more sensitive than many ordinary e-commerce transactions.ย It effectively creates a physical-world link between an individual's identity and their cryptocurrency activity.
Trezor says it is developing an Anonymous Delivery option intended to reduce that exposure.ย The planned system would reportedly include features such as:
- Locker pickup
- Neutral packaging
- Generic sender information
- Reduced shipping identifiers
- Automatic deletion of shipping information after delivery
Trezor says it is targeting availability in the EU by September 2026 and the US by the end of 2026.ย If implemented as described, that would be a meaningful privacy improvement for future customers.
๐ก Five Lessons for Crypto Users
1. Your seed phrase isn't your only security perimeter.
Your security perimeter includes:
Email โ Phone โ Identity โ Physical Address โ Exchange Accounts โ Hardware Wallet
A weakness anywhere along that chain can become an attack vector.
2. Privacy is security.
Every additional organization holding sensitive information about you creates another potential attack surface.
3. Data retention matters.
Trezor's 90-day retention policy appears to have materially constrained the historical data available in this incident.
4. Targeted phishing is more dangerous than generic phishing.
"Dear Customer" is easy to ignore.
A message containing your real name, legitimate purchase information, and actual shipping details is much harder to dismiss.
5. Self-custody doesn't eliminate human risk.
Self-custody removes the need to trust a centralized custodian with your private keys.
It does not remove:
- Social engineering
- Phishing
- SIM attacks
- Email compromise
- Malware
- Physical security risks
- Human error
Self-custody changes where the risk lives.
It doesn't make risk disappear.
โ ๏ธ Bottom Line
The Trezor incident should not be interpreted as a compromise of Trezor wallets or private keys.ย Based on Trezor's disclosure, this was a third-party fulfillment-provider breach involving customer information. The immediate danger isn't someone extracting private keys from Trezor's systems.ย The bigger danger is someone using legitimate customer information to create a convincing story and then persuading a victim to voluntarily surrender the information that actually matters.
That's why the correct response isn't panic.
- It's operational security.
- Your seed phrase stays offline.
- It stays private.
- It never goes into a website.
If anyone contacts you claiming your Trezor, your cryptocurrency, or your account needs to be "verified," "recovered," or "secured," assume the communication is fraudulent until you independently verify it.
Trezor says the hardware wallet remains secure. ๐ Make sure the person holding it is too.
๐ Source & Disclosure
Primary source: Trezor's official security announcement regarding the ShipMonk data breach, published August 13, 2026.
Status: ๐ข Current as of August 13, 2026
The investigation into the ShipMonk incident remains ongoing. Additional information may be released as Trezor and ShipMonk determine the full circumstances and scope of the breach.
This article is an independent analysis based primarily on Trezor's public disclosure. Illustrative phishing scenarios are hypothetical and are not claims about specific attacks that have occurred.