TL;DR
Trezor has disclosed a data breach at ShipMonk, one of its fulfillment partners, exposing personal information belonging to 13,689 customers who received orders between May 10 and August 8. For 11,742 people, the stolen data included full names, phone numbers, email addresses and shipping addresses, while another 1,947 had names, cities and emails exposed. The breach affected customers in seven countries across the United States, Europe and beyond. The most unsettling detail is that a hardware wallet purchase can create a physical security trail even when the wallet itself remains technically secure.
Trezor says its own systems were not compromised and that no device, private key or wallet backup was affected, separating the incident from a direct wallet-security failure. ShipMonk told the company on Monday that an unauthorized party had accessed systems containing customer information. The breach was limited by Trezor’s policy requiring partners to delete or anonymize order data 90 days after delivery. That retention rule appears to have reduced the exposure substantially, because older customer records were no longer available within the compromised environment when the attacker gained access to the data during the intrusion.

The company is now warning affected customers to treat unexpected communications with suspicion and never enter a wallet backup online. Trezor said customers who did not receive a notification email are not affected. The exposed information nevertheless gives attackers material that can make phishing attempts more convincing, particularly when names, phone numbers, emails and home addresses can be combined. The risk is no longer limited to fraudulent links or messages. Personal shipping data can connect cryptocurrency ownership with a real-world location, creating a security problem that extends beyond passwords, seed phrases and conventional account protections.
The incident is especially notable because Trezor said that in 13 years it had never previously experienced a breach exposing customer phone numbers and shipping addresses. The company’s devices and backups remain untouched, but the compromise shows how a security perimeter can extend into logistics providers that never handle private keys. The breach therefore shifts attention toward operational data held around hardware-wallet purchases rather than the cryptography protecting the wallets themselves. For affected customers, the immediate challenge is managing exposure created by leaked contact and location information while avoiding targeted phishing or other social-engineering attempts.