TL;DR

  • A data breach exposed personal information belonging to 13,689 Trezor customers through shipping provider ShipMonk.
  • Home addresses and phone numbers were exposed for 11,742 customers, while another 1,947 had partial records involved.
  • Trezor says wallets and private keys were not compromised, but the leaked information could support more targeted phishing attempts.

A data breach at Trezor’s shipping provider ShipMonk exposed personal information belonging to 13,689 hardware-wallet customers. The records included home addresses and phone numbers for 11,742 of them, creating a risk of targeted phishing and other scams.

Trezor disclosed the incident on August 13, three days after ShipMonk reported unauthorized access, and says its devices, private keys and internal systems were not compromised. So far, the company has not linked any crypto theft or scam to the exposed data.

What the ShipMonk breach exposed

The larger group of 11,742 customers had their names, email addresses, phone numbers and shipping addresses exposed. Another 1,947 customers had names, cities and email addresses involved.

The main affected group received Trezor orders between May 10 and August 8, 2026. The affected customers live in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.

Trezor says it is still verifying with ShipMonk how some orders older than 90 days ended up in the partial-exposure group. Customers who bought through Amazon were not affected because another provider handled those deliveries, Trezor told CoinDesk.

Trezor says it emailed every affected customer from its official support address. According to the company, people who did not receive that notification were not included in the breach.

How the breach affects wallet security

Hardware wallets keep the private keys needed to authorize crypto transactions off any internet-connected computer. The customer data ShipMonk handled for order fulfilment never touched the devices at all. The leaked records cannot unlock a wallet, but they can help a criminal identify someone as a likely crypto owner and craft a message tailored to that person.

Trezor warned that affected customers may receive fraudulent emails, phone calls or letters. For example, a scammer could impersonate Trezor, a bank or a crypto exchange and ask for a wallet backup or other sensitive information.

The company says users should never enter a wallet backup on a website or share it with anyone. It recommends checking unexpected messages against notices on Trezor’s blog and official social accounts.

A software flaw may explain the access

Trezor has not published a full technical account of the ShipMonk breach. However, BleepingComputer reported that ShipMonk attributed the exposure to a vulnerability in Metabase, an analytics platform used to work with company data.

Metabase disclosed the previously unknown flaw on August 6, saying an attacker could gain administrator access, read information available through connected databases and export data. The company patched its cloud service and told self-hosted users to update immediately.

ShipMonk said the software vendor had patched the vulnerability and invalidated active sessions, according to customer notices reviewed by BleepingComputer. ShipMonk began an external technical investigation.

Several details remain unconfirmed. Neither Trezor nor ShipMonk has said when the unauthorized access began or how long it lasted.

What happens next

Trezor says it has no confirmed evidence that anyone published, sold or used the records in an attack. Still, contact details can remain useful to scammers long after a breach.

An Anonymous Delivery option is planned for the European Union in September and the US by the end of 2026, offering locker pickup, neutral packaging and automatic deletion of shipping identifiers after delivery.

The company says its 90-day retention policy limited the exposure because fulfilment providers must delete or anonymize older order data. That safeguard reduced the available records, but it did not protect customers whose details were still needed for recent deliveries and returns. The most concrete unresolved question is how some of the 1,947 partial records came to include orders outside that window. Trezor says it is working with ShipMonk to confirm the exact timeframe and will update its public FAQ once that is settled.

1 COMMENT

LEAVE A REPLY

Please enter your comment!
Please enter your name here