Trezor said personal information tied to roughly 13,700 customers was exposed after a breach at ShipMonk, a shipping provider that handled some orders for the hardware wallet maker. According to Trezor, ShipMonk reported that an unauthorized party accessed systems containing customer order information.
The company said the incident affected customers in seven countries. Trezor added that its own internal systems were not breached and that the incident did not compromise its hardware wallets.
What information was exposed
Trezor said 11,742 customers had a fuller set of details exposed, including names, email addresses, phone numbers and shipping addresses. A further 1,947 customers had names, cities and email addresses leaked.
Taken together, the two groups bring the number of affected customers to about 13,700. Trezor described the incident as the first time since its founding in 2013 that a breach had exposed customer phone numbers and shipping addresses.
How the breach happened
The company attributed the exposure to ShipMonk rather than to a compromise of Trezor’s own systems. ShipMonk told Trezor that an unauthorized party had gained access to systems that stored customer order data.
Based on Trezor’s account, the breach was limited to information held by the shipping partner. The company said there was no impact on the security of its hardware wallets.
Why the exposed data matters
Even without access to wallet devices or Trezor’s internal systems, the leaked details could still create risks for affected users. Personal data such as names, email addresses, phone numbers and location information can make phishing attempts appear more credible if attackers impersonate Trezor, banks or crypto exchanges.
Shipping information may also raise physical safety concerns for crypto holders, whose assets can make them attractive targets. The article notes that such incidents can widen the threat beyond online fraud, especially when criminals can tie contact details to home delivery information.
Broader context and next steps
The breach underscores a recurring problem for crypto companies that rely on outside service providers to process orders or customer data. A similar case affected Ledger in 2020, when information tied to more than 270,000 customers was exposed.
The source article also points to a wider backdrop of threats against crypto holders, saying more than $30 million was stolen in violent attacks during the first half of 2026. For now, the confirmed facts are that ShipMonk reported unauthorized access to order systems and that Trezor says nearly 14,000 customers across seven countries were affected, while its own infrastructure and products were not compromised.
Source: Coin Edition