Trezor Customers' Data Exposed in ShipMonk Breach
A data breach at ShipMonk, one of the logistics companies that ships hardware wallets for Trezor, has exposed personal information belonging to approximately 13,689 customers.
The breach occurred between May 10 and August 8, 2026, across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. ShipMonk told Trezor on August 10, 2026, that an unauthorized party had accessed systems holding customer order data.
About 11,742 customers had their full names, emails, phone numbers, and shipping addresses exposed; another 1,947 had only names, cities, and emails leaked. Trezor devices and internal systems were not compromised, but the company warns that affected customers may see more sophisticated phishing attempts by email, phone, or postal mail.
Trezor plans to roll out an anonymous delivery option in the EU by September 2026 and in the US by the end of 2026. In the meantime, the company recommends using an anonymous email address at checkout, paying with crypto or disposable digital cards instead of a personal credit card, and using a P.O. Box where possible.