Trezor Warns 13,689 Customers To Brace For Sophisticated Phishing

Customer records for 13,689 Trezor buyers were exposed in the ShipMonk fulfillment breach, raising the risk of targeted phishing. (Image: Shutterstock)
Customer records for 13,689 Trezor buyers were exposed in the ShipMonk fulfillment breach, raising the risk of targeted phishing. (Image: Shutterstock)

A data breach at Trezor's shipping partner ShipMonk exposed personal order details belonging to 13,689 customers of the hardware wallet maker, the company said Thursday.

Key Points:

  • ShipMonk, a Trezor fulfillment partner, was breached, exposing names, addresses, phone numbers and emails.
  • Full records were taken for 11,742 customers, with partial records exposed for another 1,947.
  • Trezor says its systems, devices, private keys and wallet backups were untouched.

ShipMonk Breach Exposes Trezor Order Data

ShipMonk told Trezor on Aug. 10 that an unauthorized actor had reached internal systems holding customer order records, the wallet maker disclosed on Thursday.

Some 11,742 customers had names, phone numbers, email addresses and shipping addresses taken, while another 1,947 had names, cities and email addresses exposed. Those affected placed orders between May 10 and Aug. 8 that shipped to the United States, Britain, Sweden, Colombia, Brazil, Italy or Portugal.

Trezor said its own systems were not compromised and that no device, private key or wallet backup was touched, and the investigation is continuing. A 90-day deletion rule imposed on fulfillment partners kept older orders beyond the reach of the intruder, and customers who received no notification email were not caught in the leak.

Also Read: Four Traders Bet $343M Against Bitcoin, And One Already Flinched

Phishing Risk Follows Ledger Precedent

The immediate danger is fraud, not theft from the devices themselves.

Scammers can use the leaked details to impersonate banks, exchanges or Trezor itself through email, phone calls and printed letters, the company warned. It urged customers to treat any message demanding urgent action with suspicion and to check claims against official channels. Nobody should ever type a wallet backup into a website.

Rival Ledger set the precedent in 2020, when roughly 272,000 of its customers had names, addresses and phone numbers published, and some later received ransom demands by email. CertiK verified 52 physical attacks on crypto holders in the first half of 2026, up from 39 a year earlier, while Chainalysis counted more than $30 million stolen through such assaults.

Trezor Breach History And Wallet Fallout

This is the first incident since Trezor's 2013 founding to expose customer phone numbers and shipping addresses. Earlier problems were narrower, including a 2024 compromise of a third-party support portal that exposed names and email addresses for about 66,000 users.

No customer funds were lost in that episode. The company has told buyers they can limit future exposure by using anonymous email addresses, paying in crypto or shipping to a post office box.

The disclosure also lands amid fallout from a Coldcard firmware flaw, which preceded roughly 233,000 Bitcoin (BTC) leaving long-term holder wallets, some of it moved by Trezor and Ledger owners switching to multi-signature storage, according to Casa. Trezor now plans an Anonymous Delivery option using locker pickup and neutral packaging, targeting the European Union by Sept. 2026 and the United States by year's end.

Read Next: XRP Selling Pressure Hits 0.86, Its Weakest Reading Since May

Murtuza Merchant profile photo

Murtuza Merchant

Murtuza is a seasoned finance journalist with extensive experience covering cryptocurrencies and blockchain technology. He has contributed to Benzinga and Cointelegraph, among other publications, reporting on emerging trends, the regulatory landscape, and more. Find him at @murtuza_merc on Twitter and mmerchant001 on Telegram. Disclosure: Murtuza holds ATOM, AKT, TIA, INJ, and OSMO.

page_article_disclaimer
Trezor Warns 13,689 Customers To Brace For Sophisticated Phishing | Yellow