Personal data belonging to nearly 14,000 Trezor customers has been compromised after an unauthorised party accessed systems held by ShipMonk, one of the hardware wallet maker’s fulfilment partners. Trezor disclosed the incident on Thursday, August 13, 2026.
What Was Taken
ShipMonk informed Trezor on Monday that an intruder had reached customer order data. In total, 13,689 customers were affected. Of those, 11,742 had their full names, phone numbers, email addresses, and shipping addresses taken. A further 1,947 customers had names, cities, and email addresses exposed. All affected orders were placed between May 10 and August 8, 2026, and were shipped to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal.
Trezor said customers who did not receive a notification email are not affected by the breach.
Trezor’s Own Systems Untouched
Trezor was clear that its own infrastructure was not compromised. No device, private key, or wallet backup was accessed. The company credited a 90-day data retention policy, which requires partners to delete or anonymise order data after delivery, for limiting the exposure. Older orders were no longer held in ShipMonk’s systems and were therefore not at risk. Trezor noted that in its 13-year history it had never previously suffered a breach exposing customer phone numbers and shipping addresses.
Phishing and Physical Attack Risk
Trezor’s warning to affected customers focuses on phishing. It advises users to treat unexpected contact with suspicion and to never enter a wallet backup phrase online or anywhere off the device itself.
The precedent set by the 2020 Ledger breach illustrates why the concern extends well beyond fraudulent email. After roughly 272,000 Ledger customers had their names, addresses, and phone numbers published, some received ransom demands that included threats of physical violence. One customer described receiving multiple emails and texts a day, and others later reported phishing calls from people who spoke as though they already knew them personally.
Physical risk to crypto holders has intensified more broadly. CertiK verified 52 physical attacks on crypto holders in the first half of 2026, up from 39 a year earlier, with home invasions overtaking kidnapping as the most common method. Chainalysis reported more than $30 million stolen through such attacks over the same period, putting 2026 on course to be the worst year on record for so-called wrench attacks.
Wider Pattern of Hardware Wallet Supply Chain Breaches
The ShipMonk incident is the latest in a line of third-party data exposures targeting hardware wallet customers. Ledger disclosed a breach at its own e-commerce partner, Global-e, in January 2026. Hardware wallet firms also warned of a phishing surge this month as losses connected to the Coldcard exploit approached $130 million. Around 233,000 BTC, worth roughly $15 billion, left long-term holder wallets in the aftermath of that Coldcard breach, with some of that movement coming from Ledger and Trezor owners migrating to multi-signature setups, according to Casa.
Anonymous Delivery Option Coming
Trezor announced it is accelerating an Anonymous Delivery programme that will use locker pickup points, neutral packaging, generic sender details, and automatic deletion of shipping identifiers. The company is targeting a European Union launch by September 2026, with a United States rollout by the end of the year.

