Trezor reports data from 14K users exposed through shipping provider

Editorial photo of a Trezor hardware wallet beside a sealed shipping box on a clean desk with neutral newsroom lighting.

Hardware wallet manufacturer Trezor has disclosed a data breach at third-party fulfillment provider ShipMonk that exposed personal information belonging to approximately 13,689 customers. The incident compromised customer order data, not Trezor wallets, devices or internal systems, leaving affected users primarily exposed to heightened phishing and impersonation risks.

Phishing Letters Impersonating Trezor and Ledger Again Target Hardware‑wallet Users

Editorial desk scene with a phishing letter impersonating Ledger and Trezor branding, a QR code, and seed phrase hint.

Printed phishing letters that mimicked official communications from hardware-wallet makers were mailed to Trezor and Ledger users, urging recipients to scan QR codes or visit fake websites and enter recovery seed phrases. The campaign deliberately used authoritative branding, counterfeit signatures, and hard deadlines, including February 15, 2026, to trigger rushed compliance and irreversible asset loss.