trezor
Trezor Data Breach: What ShipMonk Exposed
ShipMonk, Trezor's shipper, exposed contact data for 13,689 customers from orders shipped May to August 2026. Devices and keys were not affected.
Trezor disclosed a data breach on August 13, 2026. ShipMonk, the third-party shipping and fulfillment provider it uses for physical orders, had unauthorized access to systems holding customer order data. The number attached to the story is 13,689. What actually determines what you should do about it is what kind of number it is: a shipping database, not a seed phrase.
Quick Facts
| What happened | ShipMonk, Trezor's third-party shipping and fulfillment provider, had unauthorized access to systems holding Trezor order data. Trezor's own infrastructure was not involved. |
| Timeline | ShipMonk notified Trezor on Monday, August 10, 2026. Trezor disclosed publicly on August 13, 2026. |
| Customers affected | 13,689 total: 11,742 fully exposed, 1,947 partially exposed. |
| Data exposed (full group) | Name, email, phone number, shipping address, order number. |
| Data exposed (partial group) | Name, city, email only. |
| Data not exposed | Private keys, device data, wallet backups. Devices and firmware were not touched. |
| Countries affected | United States, United Kingdom, Sweden, Colombia, Brazil, Italy, Portugal. |
| Exposure window | Orders shipped roughly May 10 to August 8, 2026, bounded by Trezor's 90-day data retention policy. |
Sources: Trezor, The Block, Decrypt, Bitcoin.com News, crypto.news
What Happened: ShipMonk, Not Trezor's Own Systems
ShipMonk is the fulfillment company Trezor uses to pack and ship physical orders. It is not part of Trezor's own infrastructure. Trezor has been explicit about that distinction: the exposure happened on ShipMonk's systems, not on any system Trezor runs directly (Trezor). ShipMonk told Trezor about the unauthorized access on Monday, August 10, 2026. Trezor disclosed the incident publicly three days later, on August 13 (Trezor, The Block).
The Numbers: Who Was Exposed and What Data
Trezor and four independent outlets, The Block, Decrypt, Bitcoin.com News, and crypto.news, report identical figures (Trezor; corroborated by The Block, Decrypt, Bitcoin.com News, crypto.news). 13,689 customers were affected in total. Of those, 11,742 had full exposure: name, email address, phone number, shipping address, and order number. The remaining 1,947 had partial exposure: name, city, and email address only.
The affected accounts span seven countries: the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The exposure window covers orders shipped roughly between May 10 and August 8, 2026. That's a span of about 90 days.
Five independent outlets landed on the exact same numbers. None of them revised or contradicted the figures. That consistency is worth noting: it means the scope described here is settled, not still being counted.
What Wasn't Touched: Keys, Devices, and Backups
Trezor's own statement on the incident is unambiguous:
"Trezor systems, hardware wallets, private keys, and wallet backups were not affected." (Trezor)
And more directly:
"our systems were not compromised, and your Trezor device is secure." (Trezor)
The Block, Decrypt, Bitcoin.com News, and crypto.news each confirm this independently (The Block, Decrypt, Bitcoin.com News, crypto.news). No device, firmware, private key, or wallet backup was part of what ShipMonk exposed. What leaked was contact and shipping information. That's the kind of data any fulfillment vendor holds to get a box to your door, not anything cryptographic.
Why Trezor Is Calling This a First in Thirteen Years
Trezor has also been specific about how unusual this is for the company:
"This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses." (Trezor)
Decrypt and crypto.news both confirm the same framing in their own reporting (Decrypt, crypto.news). Thirteen years without this category of exposure is a real track record. It's worth stating plainly: this is not a company with a pattern of losing physical-world customer data. It is one incident, through one vendor.
The Pattern: Hardware Wallets Keep Getting Breached Through Third Parties
Zoom out and this incident fits a shape that has appeared before, and not only at Trezor. In July 2020, Ledger's e-commerce database was accessed through a compromised API key. The exposure looked small in Ledger's own July disclosure. It turned out to be far larger once the full database was dumped publicly in December 2020. That dump exposed roughly 272,000 customers' full names, postal addresses, and phone numbers, plus a much larger set of email-only records (Ledger, Bitdefender). In January 2026, Ledger disclosed a second, separate third-party breach. This time it went through Global-e, its international checkout processor. Again, the exposed data was names and contact information, not payment or seed-related data (CoinDesk, BleepingComputer).
We covered a different failure mode in this same category recently: the Coldcard RNG flaw that let attackers regenerate seeds offline. That was a firmware defect, a problem in the device itself. ShipMonk, Global-e, and Ledger's 2020 breach are a different category entirely. None of them touched a device or a key. They touched the commercial infrastructure sitting around the device: the checkout processor, the shipping vendor, the customer database. That's a separate attack surface from the cryptography. On this year's evidence, it's also the more frequently breached one.
On what happens to that kind of data once it's out, the record deserves care rather than inflation. Every outlet covering the ShipMonk breach, including Trezor, scopes the realistic downstream risk to phishing, impersonation calls, and fraudulent mail, not physical targeting.
Separately, on a different timescale, security firm CertiK's H1 2026 Intel3D report counted 52 physical "wrench attacks" against crypto holders globally in the first six months of 2026. That's a 33% increase year over year, with $124.1 million in recorded financial exposure. CertiK attributes the geographic concentration to major domestic data leaks generally, not to any single vendor breach. France accounted for roughly 64% of the global total (GlobeNewswire, Decrypt).
Reporting on the 2025 kidnapping of Ledger co-founder David Balland, and the 2026 arrest of a suspect in that case, describes the original 2020 Ledger leak as "a determining factor in victim targeting" (fibo-crypto.fr). No comparable claim exists, or is being made here, about the ShipMonk data specifically. The industry-level pattern is real. A specific claim about this specific leak's consequences needs the same caution the sourcing above requires.
The Real Risk: Phishing and Impersonation, Not Your Coins
Trezor's own warning is the accurate one, worth quoting directly rather than paraphrasing:
"Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor." (Trezor)
That is the actual threat model. Your name, email, phone number, and address are now available to make a scam feel personal. Nothing about your coins changes because of this breach. What changes is the credibility of a scam. A phishing email, a spoofed support call, or a fraudulent letter can now be addressed to you by name, at your real address. That makes it more convincing than it would otherwise be.
There is recent precedent for how far this goes. After Ledger's 2020 leak, criminals mailed counterfeit Ledger Nano devices to victims' real, leaked addresses. The devices were shrink-wrapped and branded convincingly, with instructions to "replace" their wallet. They contained malware built to capture the 24-word recovery phrase once entered. Ledger's own security team confirmed the scheme in June 2021 (Yahoo Finance). As recently as 2025, victims of the same 2020 leak were still receiving physical letters exploiting the same data (Bitbo, crypto.news).
Phishing losses tied to hardware wallets more broadly have also been a real dollar figure in 2026. Industry reporting in August put crypto phishing losses at roughly $12 million a month. Hardware-wallet-specific phishing was pushing toward $130 million (Decrypt). None of that is a prediction about what will happen to the 13,689 people in this breach. It is the honest baseline for what this category of leaked data gets used for when it does get used.
Trezor's Response and the Coming Anonymous Delivery Option
Trezor points to three concrete responses. First, a 90-day data retention policy: Trezor requires fulfillment partners, including ShipMonk, to delete or anonymize customer order data 90 days after delivery. That policy is why this exposure is bounded to roughly the May 10 to August 8, 2026 window, rather than covering Trezor's full order history (Trezor, Decrypt, crypto.news). Second, direct notification: Trezor says all affected customers were contacted individually by email (Trezor). Third, a new feature called Anonymous Delivery: locker pickup or neutral packaging, with automatic deletion of shipping identifiers after delivery. It's targeted for the European Union by September 2026 and the United States by the end of 2026 (Trezor, Decrypt, crypto.news). ShipMonk has also said it secured and hardened the affected systems, per outlets aggregating the vendor's response (cybersecuritynews.com).
What To Do If You've Ordered Hardware Recently
None of this requires panic, and Trezor's own guidance lines up with standard practice for a breach of this kind.
- Never enter your seed phrase anywhere except directly on your hardware device, during a recovery you started yourself. Not on a website, not read aloud on a call, not photographed for "support." No legitimate vendor, Trezor included, will ever ask for it (Trezor).
- Verify independently. If a message claims to be from Trezor, your bank, or an exchange, go to the official site or app yourself. Don't use any link or number the message provided (CISA).
- Treat an unsolicited "replacement device" as suspicious by default. The Ledger precedent above is the exact playbook to watch for. Don't plug in or follow instructions from hardware you didn't order.
- Lock your phone account against SIM swaps. Your phone number is part of what leaked. Current FCC rules require carriers to offer an account PIN or lock. Carriers must also notify you of change or port-out requests (Krebs on Security).
- If you're in the US, consider registering your own USPS Informed Delivery account before someone else does. Only one account is allowed per address. It previews incoming mail by photo (Vivint).
- Standard breach hygiene still applies. IdentityTheft.gov is the FTC's standard first stop if you see actual identity-theft symptoms. Credit freezes are free and reversible (FTC).
Frequently Asked Questions
Was my Trezor hardware wallet or private keys compromised in the ShipMonk breach?
No. Trezor states that devices, firmware, private keys, and wallet backups were not affected. The exposure was limited to order and shipping data held by a third-party fulfillment vendor (Trezor).
How many customers were affected?
13,689 total. 11,742 had full contact data exposed: name, email, phone, address, order number. The remaining 1,947 had partial exposure: name, city, email (Trezor).
What should I do if I ordered a Trezor between May and August 2026?
Expect a direct notification email from Trezor if you were affected. Treat unsolicited calls, texts, or "replacement device" mail referencing your order as suspicious. Verify any communication by going to trezor.io directly, rather than through a link or number it provided (Trezor).
Is this Trezor's first data breach?
Trezor was founded in 2013. This is the first breach in the company's history that exposed customer phone numbers and shipping addresses specifically, according to Trezor's own statement (Trezor).
How does this compare to the 2020 Ledger breach?
Same category of failure: a third-party commercial system, not the device itself. So far it's smaller in scale: 13,689 people here, versus roughly 272,000 in Ledger's eventual 2020 disclosure. Trezor's 90-day vendor data retention policy is the specific reason this incident didn't cover Trezor's full order history the way Ledger's did (Ledger, Bitdefender, Trezor).
Where NexusPool Fits
NexusPool is a mining pool, not a hardware wallet vendor. It doesn't have a fulfillment vendor holding customer shipping data, because it doesn't ship anything. That's a scope difference, not a claim that mining pools are inherently safer than hardware wallet companies. They're different products with different attack surfaces. This incident says nothing about either category being more or less trustworthy in general.
What is genuinely relevant is the underlying theme. NexusPool is non-custodial: a solved block pays your address directly, at 0% fee. Nothing is routed through a balance you'd have to trust a third party to honor. The Glass Ledger, our proof-of-custody system, exists for the same reason Trezor tells you to verify its communications yourself. The point isn't to ask you to trust us. It's to give you something you can check.
Trust nothing. Verify any message claiming to be Trezor against trezor.io yourself, never against the number or link it arrived with.
Sources
- Trezor: "Recent customer data exposed in shipping provider incident"
- The Block: "Trezor shipping provider breach exposes personal data of nearly 14,000 customers"
- Decrypt: "Trezor Customer Data Exposed in Shipping Partner Breach"
- Bitcoin.com News: "Trezor Shipping Provider Exposes 13,689 Crypto Customers to Scams"
- crypto.news: "Trezor says ShipMonk breach exposed data of 13,689 customers"