Trezor Data Breach Exposes Nearly 14,000 Customers as Shipping Partner's Systems Compromised
Trezor, a hardware wallet maker, has disclosed that nearly 14,000 customers' personal information was exposed in a data breach at ShipMonk, its third-party logistics partner. The compromised data includes customer names, email addresses, phone numbers, and complete shipping addresses for those who ordered Trezor devices shipped between May 10 and August 8, 2026.
The company stressed that its core products, wallet backups, and customer funds remain untouched, but security researchers warn that the leaked data still poses a significant risk to targeted cryptocurrency holders. A leaked list of hardware wallet customers can be used by attackers to launch convincing social engineering campaigns via email, SMS, phone calls, or even physical mail.
Trezor is urging affected customers to review their personal security practices and take precautions such as using a dedicated email for crypto-related purchases, paying with cryptocurrency or disposable virtual cards, and verifying all communications through official channels only. The company has also announced plans for an Anonymous Delivery option designed to prevent similar exposure in the future.
The incident highlights the importance of attention not just to device-level security but also to the entire chain of vendors and services that touch a customer's information along the way.