Trezor Data Breach Hits 14,000 Customers Through Shipping Partner
Security

Trezor Data Breach Hits 14,000 Customers Through Shipping Partner

August 13, 20264 min read

Hardware wallet maker Trezor has warned roughly 14,000 customers about a personal data breach at one of its shipping partners. Those affected placed orders between May 10 and August 8 and had them shipped to the US, UK, Sweden, Colombia, Brazil, Italy or Portugal. The episode echoes Ledger's 2020 breach and shows that protecting private keys covers only part of a crypto holder's security picture.

What happened at ShipMonk's warehouse

ShipMonk, which stores and ships Trezor's products, told the company on Monday that an unauthorized party had reached systems holding customer data. The scope turned out to be sizable. Attackers took the full data set of 11,742 customers: name, address, phone number and email. Another 1,947 people had only names, cities and email addresses exposed. That adds up to 13,689 affected accounts, close to the 14,000 figure in most headlines.

Trezor stressed that its own systems were not touched. No device, private key or wallet backup was put at risk. The limited scope has a simple explanation. Partners are required to delete or anonymize order data 90 days after delivery, so older orders were simply gone from ShipMonk's system by the time of the breach. Customers who did not receive a warning email from Trezor were not affected. For the 13,689 people caught in that window, though, the consequences are quite real.

Who is at risk, and how

Trezor's warning is mainly about phishing. The company advises wallet owners to treat any unexpected call, email or message that claims to come from support with suspicion. The core rule stays the same. A seed phrase or wallet backup should never go into any website or app, no matter how convincing the request looks.

The risk does not stop at email. Attackers now hold full shipping addresses and phone numbers tied to real hardware wallet owners. That moves the threat into physical safety, not just cybersecurity, which is exactly why Trezor is choosing its words carefully.

Impact: Attackers walked away with home addresses and phone numbers, not just emails, raising the stakes beyond phishing toward real-world threats against specific people.

The risk goes beyond phishing

There is precedent. Ledger was breached in 2020, exposing names, addresses and phone numbers of about 272,000 customers. Some later received ransom demands threatening violence, while others described calls from people who seemed to know far too much about them. That breach was long treated as the worst the hardware wallet industry had seen. It now has a rival in impact, even with a smaller customer count this time.

CertiK confirmed 52 physical attacks on crypto holders worldwide in the first half of 2026, up from 39 a year earlier. Home invasions have overtaken kidnapping as the most common method. Chainalysis put total losses from such attacks over the same period above $30 million and expects the year to end as the worst on record. Against that backdrop, any fresh database of hardware wallet owners' addresses reads like a ready-made target list.

Hardware wallets keep getting hit

This is not the first such incident in the hardware wallet supply chain. Ledger disclosed a breach at its e-commerce partner Global-e in January. This month, wallet makers warned of a phishing surge tied to the Coldcard exploit, with losses approaching $130 million.

That same Coldcard incident pushed some large bitcoin holders to act. According to Casa, roughly 233,000 Bitcoin, worth about $15 billion, moved out of long-term holder wallets, and part of that sum belonged to Ledger and Trezor owners shifting to multisig setups. Hardware vendors now find themselves in an odd spot, where the device stays secure while everything surrounding it turns into a weak point.

In practice, hardware wallet owners tend to respond to news like this in similar ways.

  • they check whether their data shows up in known leak databases.
  • they move private keys into multisig storage.
  • they ignore calls and emails asking them to confirm wallet details.
  • they update shipping addresses ahead of any future hardware purchases.

What changes in Trezor's shipping

Trezor said that in 13 years of operating, this is the first breach to expose customer phone numbers and addresses. In response, the company is fast-tracking an Anonymous Delivery option. It includes locker pickup, neutral packaging without logos, anonymized sender details, and automatic deletion of shipping identifiers. The option launches in the EU as soon as September and in the US by year-end.

For the hardware wallet market, this is another signal. A crypto owner's home address has become as valuable a target as the device itself. Vendors that used to compete purely on firmware security now have to defend their logistics chain too, and buyers are increasingly weighing how a company handles their data before they pick a wallet.

Comments

Your email address will not be published. Required fields are marked *

or verify by email