Trezor is warning roughly 13,689 customers that their personal data was exposed after ShipMonk, one of the hardware wallet maker's shipping fulfilment partners, suffered unauthorized access to its systems. The company said the breach touched orders shipped between May 10 and August 8, 2026, and does not involve Trezor's own infrastructure, devices or firmware.
Of the affected customers, 11,742 had their full name, email address, phone number and shipping address exposed, while a further 1,947 had a narrower set of data compromised — name, city and email address. Shipments tied to the breach spanned the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor said customers who ordered through Amazon, which uses a separate fulfilment partner, were not affected.
Trezor says wallets and keys were never at risk
Trezor emailed affected customers directly, telling them:
"Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data."
The company was explicit that the incident sits entirely outside its own security perimeter, adding that private keys, wallet backups and device firmware remain untouched. Trezor said it has seen no confirmed cases of the stolen data being published or sold, and no scams linked to the breach so far — though it warned customers to expect more convincing phishing attempts, including fake emails, calls or letters impersonating Trezor, a bank or an exchange.
A recurring problem for hardware wallet makers
This is the first incident in Trezor's 13-year history to expose customer phone numbers and physical addresses, following smaller breaches that affected roughly 66,000 users in January 2024 and about 106,856 in April 2022.
Related: Whale Loses $26M in Private Key Breach, Two Years After a $24M Phishing Hit
The pattern is familiar across the industry: rival Ledger has been hit by data exposures through third-party partners multiple times, including a 2020 breach through Shopify that leaked 270,000 customers' shipping details and led to some recipients receiving ransom demands threatening physical violence, and a more recent leak traced to payment processor Global-e. In both cases, and again with Trezor, the wallets themselves were never compromised — the exposure came entirely from vendors handling shipping and payment logistics.
The breach also lands amid a broader surge in data breach activity: the Identity Theft Resource Center's 2026 Trends in Identity Report found identity crimes increasingly "multi-layered," with more than a quarter of victims now juggling two or more concurrent incidents. For hardware wallet owners specifically, a leaked shipping address is a higher-stakes exposure than an ordinary email leak, since it can be used to identify and target likely holders of physical crypto devices. Trezor said it plans to roll out an Anonymous Delivery option in the EU by September 2026 and in the U.S. by year-end to reduce this kind of exposure going forward.