Hardware wallet manufacturer Trezor has disclosed a data breach at third-party fulfillment provider ShipMonk that exposed personal information belonging to approximately 13,689 customers. The incident compromised customer order data, not Trezor wallets, devices or internal systems, leaving affected users primarily exposed to heightened phishing and impersonation risks.
ShipMonk notified Trezor on August 10 that an unauthorized party had accessed systems containing customer information. In its official August 13 security notice, Trezor said customers receiving orders in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal could be affected. The investigation remains ongoing as Trezor and ShipMonk work to determine the full scope of the unauthorized access.
Shipping Data Creates a Targeted Phishing Risk
Trezor divided the exposure into two groups. Some 11,742 customers had names, email addresses, phone numbers and shipping addresses compromised, while another 1,947 had names, cities and email addresses exposed. The combination of contact information and physical addresses could allow attackers to craft unusually convincing phishing attempts targeting hardware-wallet owners.
The company initially linked affected orders to deliveries between May 10 and August 8, reflecting its policy requiring fulfillment partners to delete or anonymize customer data 90 days after delivery. However, Trezor later said the 1,947 customers in the partial-exposure group may include older orders and that it is verifying the exact timeframe with ShipMonk. The 90-day retention policy limited the amount of full customer information available in the breached systems, but it did not eliminate exposure entirely.
Crucially, Trezor said no product, service or company system was compromised and that its hardware wallets remain secure. Affected customers have been contacted directly by email. Possession of names, phone numbers and addresses does not provide attackers with wallet keys, but it creates valuable information for social-engineering campaigns designed to trick users into surrendering them. Trezor reiterated that customers should never enter wallet backups on websites or disclose recovery information to anyone.
Trezor Plans More Private Hardware Deliveries
The breach is also prompting changes to Trezor’s fulfillment model. The company plans to introduce an Anonymous Delivery option using a dedicated checkout process, locker collection, neutral packaging and generic sender information. The proposed system is designed to automatically remove shipping identifiers after delivery, reducing the amount of sensitive customer information retained by logistics providers.
Trezor expects Anonymous Delivery to become available in the European Union by September 2026 and in the United States by the end of the year. ShipMonk has meanwhile secured and hardened the affected systems, according to Trezor. The incident demonstrates how hardware-wallet security can extend beyond cryptography and device design to the personal data handled by external companies responsible for getting those devices into customers’ hands.








