Published Invest3 min read
Trezor's breach wasn't at Trezor, and that is the point
A fulfillment partner, ShipMonk, lost the names, phones and home addresses of thousands of hardware wallet buyers. The key material is fine. The list is the problem.
Context for builders, not their beat.See today for builders

What happened
- Trezor disclosed on Thursday that a data breach at one of its shipping providers exposed customer names, phone numbers, email addresses and home addresses.
- A breach at ShipMonk, one of Trezor's fulfillment partners, exposed personal data belonging to 13,689 Trezor customers, with full names, phone numbers, email addresses and shipping addresses taken for 11,742 of them.
- ShipMonk, which stores and ships Trezor's products, told the company on Monday that an unauthorized party had reached systems holding customer data.
- Trezor said its own systems were not compromised and that no device, private key or wallet backup was affected.
- The total number of affected Trezor customers was 13,689.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
Trezor disclosed on Thursday that a breach at ShipMonk, one of the fulfillment partners that stores and ships its products, exposed personal data belonging to 13,689 of its customers [1][2][3]. No cryptographic material was involved: Trezor says no device, private key or wallet backup was touched and that its own systems were not compromised [4].
That distinction is doing a lot of work, and it is worth being precise about what it does and does not cover. For 11,742 of the affected customers, roughly 86 percent of the total, the exposed set includes full name, phone number, email address and shipping address [2][5][1]. The remaining 1,947 had names, cities and email addresses taken [6]. ShipMonk told Trezor on Monday that an unauthorized party had reached systems holding the data [3]. Affected orders were placed between May 10 and August 8 and shipped to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy or Portugal [7]. Trezor disclosed the incident publicly on August 13, 2026 [8].
A hardware wallet exists so that the secret never leaves the device. The order record leaves the company by design. Someone has to pick, pack and deliver a physical object to a physical door, which means a third party holds a list of people who have self-identified as owning enough crypto to buy dedicated custody hardware, indexed by home address and mobile number. That is not a phishing list. It is a targeting list.
The precedent is documented. After roughly 272,000 Ledger customers had names, addresses and phone numbers published in 2020, some began receiving ransom demands threatening violence, one told Decrypt they were getting multiple emails and texts a day, and others later reported phishing calls from people who spoke as though they knew them [9]. The base rate has since moved. CertiK verified 52 physical attacks on crypto holders worldwide in the first half of 2026, up from 39 a year earlier, an increase of about a third, with home invasions overtaking kidnapping as the most common method [10][2]. Chainalysis put the amount stolen in those attacks at more than $30 million over the same period and said the year was on course to be the worst on record [11].
Trezor's mitigation is retention policy, and it appears to have worked as designed. The company requires partners to delete or anonymize order data 90 days after delivery, which is why older orders were not held [12]. The exposed order window, May 10 to August 8, is itself 90 days [7][3]. In 13 years, Trezor says, it has never before had a breach exposing customer phone numbers and shipping addresses [13]. Customers who did not receive a notification email are not affected, according to the company [14].
This is a pattern in the vendor chain rather than one firm's failure. Ledger disclosed a breach at its own e-commerce partner, Global-e, in January [15]. Hardware wallet firms warned of a phishing surge this month as losses from the Coldcard exploit approached $130 million [16].
Watch the delivery layer. Trezor says it is pulling forward an Anonymous Delivery option using locker pickup, neutral packaging, generic sender details and automatic deletion of shipping identifiers, aimed at the European Union by September and the United States by year end [17]. Watch also whether existing owners keep restructuring rather than waiting: Casa says some of the 233,000 BTC that left long-term holder wallets around the Coldcard breach, worth roughly $15 billion, came from Ledger and Trezor owners moving to multi-signature setups, not from Coldcard customers [18].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Trezor disclosed on Thursday that a data breach at one of its shipping providers exposed customer names, phone numbers, email addresses and home addresses.
- [2]
A breach at ShipMonk, one of Trezor's fulfillment partners, exposed personal data belonging to 13,689 Trezor customers, with full names, phone numbers, email addresses and shipping addresses taken for 11,742 of them.
- [3]
ShipMonk, which stores and ships Trezor's products, told the company on Monday that an unauthorized party had reached systems holding customer data.
- [4]
Trezor said its own systems were not compromised and that no device, private key or wallet backup was affected.
- [5]
The total number of affected Trezor customers was 13,689.
- [6]
Another 1,947 affected customers had names, cities and email addresses exposed.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- decrypt.coDecrypt AgentAug 13Trezor Customer Data Exposed in Shipping Partner Breach
Additional citations
- Decrypt
- Trezor, via Decrypt
- Trezor (@Trezor) on X, via Decrypt
- CertiK, via Decrypt
- Chainalysis, via Decrypt
- Casa, via Decrypt


