Published Security3 min read
Trezor was not breached. 13,689 of its customers were.
A fulfillment partner exposed names, addresses and phone numbers belonging to hardware wallet buyers, according to The Register. The vendor's boundary was the company's boundary.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Coverage from The Register, as summarised by SC World, indicates that cryptocurrency hardware wallet maker Trezor has confirmed a data breach impacting over 13,000 of its customers.
- The breach occurred through a third-party shipping partner, ShipMonk, and exposed sensitive personal information.
- The exposed data includes names, email addresses, phone numbers and shipping addresses for 11,742 customers in several countries.
- The exposed data also includes names, home cities and email addresses for an additional 1,947 customers.
- The two disclosed groups total 13,689 affected customers.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Trezor, which makes cryptocurrency hardware wallets, has confirmed a data breach affecting more than 13,000 of its customers, according to coverage from The Register summarised by SC World [1]. The intrusion did not happen at Trezor: it happened at ShipMonk, the third-party shipping partner that moves the company's boxes [2].
The numbers are worth reading carefully, because they describe two different exposures. For 11,742 customers across several countries, the leaked set includes names, email addresses, phone numbers and shipping addresses [3]. For a further 1,947, it includes names, home cities and email addresses [4]. That is 13,689 people in total [5], of whom roughly 86 percent now have a full delivery address in the hands of whoever took the data [6].
An email list is a nuisance. A name attached to a residential address, attached to the fact that the person at that address bought a device whose entire purpose is holding bearer assets, is a different category of record. Trezor has told users its own systems remain secure and warned them to expect more phishing [7]. The phishing warning is correct and also the least of it, because the phone numbers and street addresses in the 11,742-record tranche support approaches that do not arrive by email.
The scoping has already moved once. The breach was initially believed to touch only recent orders; newer information indicates older orders may be affected too [8]. This is the ordinary shape of a vendor incident. The company that owns the customer relationship does not own the logs, the retention schedule, or the forensic timeline, so the first number it publishes is the number the vendor was able to give it that day. Operators reading this should assume the same pattern applies to their own fulfillment partners: the initial blast radius is an estimate produced by someone else's incident response team.
The structural point is unglamorous. Anyone shipping physical goods hands a third party the exact dataset that regulators, extortionists and stalkers care most about, and does it as a routine cost of doing business. There is no way to ship a parcel without a name and an address existing somewhere outside your perimeter. Most companies treat that handoff as a procurement question rather than a security boundary, which means it gets a contract and an invoice but not a retention limit, an access review, or a breach clock anyone has tested.
Trezor's remedy is the interesting part of the response. The company is building an "Anonymous Delivery" option, due in the EU in September and in the US by the end of the year, which would let customers complete orders without linking personal identification to their shipping details [9]. That is data minimisation at the vendor boundary rather than a promise to pick better vendors, and it is the only category of fix that survives the next fulfillment breach. It also arrives after the fact for 13,689 people [5].
Worth watching: whether the affected count moves again as older orders are reconciled [8], and whether Anonymous Delivery ships on the stated schedule or slips past the year-end US date [9].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Coverage from The Register, as summarised by SC World, indicates that cryptocurrency hardware wallet maker Trezor has confirmed a data breach impacting over 13,000 of its customers.
- [2]
The breach occurred through a third-party shipping partner, ShipMonk, and exposed sensitive personal information.
- [3]
The exposed data includes names, email addresses, phone numbers and shipping addresses for 11,742 customers in several countries.
- [4]
The exposed data also includes names, home cities and email addresses for an additional 1,947 customers.
- [7]
Trezor has assured users that its own systems remain secure and warned of a potential increase in phishing attempts.
- [8]
While the breach was initially believed to affect only recent orders, new information suggests older orders may also be compromised.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- scworld.comSC StaffAug 14Trezor confirms shipping partner data breach affecting over 13,000 customers
Additional citations
- SC World, citing The Register



