Hardware wallet maker Trezor has disclosed that a breach at third-party shipping and fulfillment provider ShipMonk exposed personal and order data belonging to 13,689 recent customers. Trezor said on August 10 that ShipMonk had reported unauthorized access to systems holding customer order information.

The exposure wasn't uniform across affected customers. Of the 13,689 total, 11,742 had full exposure — name, email address, phone number and shipping address — while the remaining 1,947 had partial exposure limited to name, city and email. The breach covered orders placed between May 10 and August 8, 2026, with affected shipments spanning the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

Trezor Breach Exposes Data of 13,689 Customers via Shipping Partner
Image via @WuBlockchain on X

Root Cause Traced to a Third Vendor

The chain of custody behind the breach runs even further from Trezor than a single fulfillment partner. On August 6, 2026, analytics provider Metabase informed ShipMonk that an unauthorized party had exploited a vulnerability in Metabase's own software to access ShipMonk's customer account data. In other words, the exposure passed through two separate third-party vendors before it ever touched Trezor customer information. Trezor laid out the full timeline and its response in its own incident disclosure.

No Wallets or Firmware Touched, But Real Risk Remains

Trezor emphasized that the incident did not touch its infrastructure, wallets or firmware — the breach exposed shipping and contact data only. That's still meaningful risk for a hardware-wallet company's customer base specifically: a leaked home address tied to a confirmed Trezor purchase is exactly the kind of signal attackers look for when targeting people they can reasonably assume hold meaningful crypto balances, whether through phishing, physical mail scams, or more direct social-engineering attempts. Trezor noted this is the first breach since the company's founding in 2013 to expose customer phone numbers and home addresses.

Related: Fake Hyperliquid Google Ad Drains About $550,000 From Users

A Response Aimed at Removing the Data Entirely

Trezor's fix targets the underlying exposure surface rather than just this one incident. The company said it plans to roll out an “Anonymous Delivery” option in the European Union by September 2026 and in the U.S. by the end of the year, including locker pickup and automatic deletion of shipping identifiers once a delivery is complete — an approach meant to ensure future orders leave less identifying data sitting with any shipping vendor in the first place.