Trezor Users Exposed: Data Breach Puts Physical Safety at Risk
A data breach at ShipMonk exposed customer information for over 13,689 Trezor hardware wallet buyers, including delivery addresses for nearly 12,000 people. The breach occurred between May 10 and August 8, with customers' names, email addresses, phone numbers, and shipping addresses compromised.
Trezor's own systems, devices, and services remain secure, but the exposure creates a risk: linking identifiable individuals to their homes and potential crypto holdings. Scammers could use this information to tailor phishing attacks, impersonate Trezor or financial institutions, or even conduct physical attacks on affected households.
Chainalysis reported that violent crypto attacks have surged in 2026, with home invasions accounting for 37% of incidents, up from 26% in 2023. The firm also noted a record $58 million stolen through such attacks last year and another $30 million already this year.
Trezor is taking steps to mitigate the risk, introducing Anonymous Delivery in the European Union by September 2026 and in the US by the end of the year. The service uses a dedicated checkout process, locker pickup, neutral packaging, and generic sender details, with shipping identifiers automatically deleted after delivery.