Hardware wallet maker Trezor has disclosed a data breach at ShipMonk, its third-party shipping and logistics provider, exposing personal information for nearly 14,000 customers who ordered devices between May 10 and August 8, 2026. ShipMonk notified Trezor of the unauthorized access on Monday, August 10, after attackers exploited a vulnerability in Metabase, a third-party analytics platform ShipMonk uses internally.

According to Trezor's own disclosure, 11,742 customers had their full name, email, phone number and shipping address exposed, while a further 1,947 customers had partial data — name, city and email — compromised. Affected customers span the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

Trezor Shipping Partner Breach Exposes Data of Nearly 14,000 Buyers
Image via @WuBlockchain on X

What Wasn't Compromised

Trezor emphasized that its own infrastructure, devices, firmware and private keys were not touched by the breach — the exposure was limited entirely to ShipMonk's systems and the order-fulfillment data it held on Trezor's behalf. That distinction matters for a hardware wallet company specifically, since a breach of private key material or device firmware would represent a fundamentally more severe class of incident than exposed shipping records.

Binance founder Changpeng “CZ” Zhao weighed in publicly on the incident, warning that the leaked data could expose affected customers to phishing, social engineering, and physical security risks, since the breach directly links real-world identities and home addresses to confirmed cryptocurrency hardware wallet ownership — information that is typically far more sensitive for a crypto holder than for a general e-commerce customer.

Related: Anthropic Study Finds AI Agents Sabotage Each Other With Malware

A Structural Risk of Physical Hardware Wallets

CZ's warning pointed to a broader tradeoff inherent to hardware wallets as a category: buying and shipping a physical device necessarily creates a real-world paper trail linking a person's identity and address to their crypto holdings, a link that software or self-custody wallets without a physical shipment don't carry in the same way. Scammers can use exposed shipping data of this kind to send convincing fake emails, phone calls or letters impersonating Trezor, a bank or an exchange, or in more severe cases to identify high-value targets for physical theft attempts.

Trezor said it is notifying all affected customers directly and has begun working with ShipMonk to confirm the vulnerability has been closed, though the company has not indicated whether it will change its shipping-fulfillment arrangements as a result of the incident.