Newsroom
13 August, 2026 / News / AI / Tags: trezor, shipmonk, customers, exposed, email

Unauthorized access at the shipping provider revealed names, contact details and addresses for recent orders across seven countries, while Trezor stressed its own systems and devices remained secure
Hardware wallet maker Trezor has confirmed that a security incident at third-party logistics provider ShipMonk exposed personal and order information belonging to 13,689 customers. The company stated that its internal systems and hardware devices were not affected.
ShipMonk notified Trezor on August 10 of unauthorized access to systems holding customer data. The investigation into the incident continues. Affected orders were those delivered between May 10 and August 8 in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
Of the total, 11,742 customers had their full name, email address, phone number and shipping address compromised. A further 1,947 customers saw their name, city and email address exposed. Order numbers associated with the deliveries were also held in the affected systems.
Trezor attributed the limited number of records involved to its 90-day data retention policy, which applies to the company and its fulfillment partners. Information tied to older orders had already been deleted or anonymized and was not present in the systems accessed.
This marks the first time since Trezor’s founding in 2013 that a breach involving the company or a provider has exposed customer phone numbers and shipping addresses.
All affected customers received separate email notifications from [email protected]. Individuals who did not receive such a message were not impacted, according to the company.
ShipMonk has secured and hardened the affected systems. Trezor and the provider continue working to determine precisely how the unauthorized access occurred and which specific data was viewed.
Trezor reiterated that its hardware wallets remain secure and that no private keys or device systems were compromised.
The company warned that the leaked details could enable more convincing phishing attempts. Attackers might use the information to send fake emails, place phone calls or mail letters while impersonating Trezor, a bank or a cryptocurrency exchange.
Customers were advised never to enter a wallet recovery phrase on any website or share it with anyone, and to verify all communications against official Trezor channels.
Because most of the records include the physical delivery address linked to a recent Trezor order, the exposure also creates a potential physical security concern for the individuals involved.
Trezor plans to introduce an Anonymous Delivery option intended to reduce the personal data retained during shipments. The feature is scheduled for availability in the European Union by September 2026 and in the United States by the end of 2026. It is expected to incorporate locker collection points and automatic deletion of shipping identifiers after delivery.
In the meantime, the company suggested customers consider using an email address not tied to their primary identity, paying with cryptocurrency where possible, and employing a post office box when available to limit exposure of home addresses.









