Trezor Shipping Partner Breach Exposes Data of 13,689 Customers
A security failure at fulfillment provider ShipMonk leaked home addresses and contact details for hardware wallet users across seven countries.
Trezor disclosed on August 13, 2026, that a data breach at its third-party fulfillment partner, ShipMonk, exposed the personal information of thousands of customers. The leak places hardware wallet users at an elevated risk of sophisticated phishing and targeted social engineering attacks.
According to company disclosures, the incident affected approximately 13,689 customers who placed orders between May 10 and August 8, 2026. The scale of the exposure varied among the victims: 11,742 customers had their full names, email addresses, phone numbers, and home addresses leaked, while another 1,947 had their names, cities, and emails exposed. The breach impacted users across seven different countries, including the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal.
System Integrity and Scope
Trezor emphasized that the breach occurred exclusively within ShipMonk's systems and did not involve Trezor's internal infrastructure. Crucially, the company confirmed that no private keys, wallet backups, or hardware wallet data were compromised during the event. The window of exposure was limited to recent orders due to a corporate policy requiring partners to delete customer order data within 90 days.
The Rise of Physical Risk
While the theft of seed phrases was avoided, the exposure of home addresses and phone numbers creates a distinct security vulnerability known as "physical phishing." In the cryptocurrency sector, the combination of a known home address and the confirmed ownership of a hardware wallet transforms a user into a high-value target for extortion and home invasions.
This incident arrives during a period of increasing physical threats against digital asset holders. Data from CertiK indicates that there were 52 reported physical attacks, often referred to as "wrench attacks," targeting crypto holders in the first half of 2026 alone. The leak of residential data provides bad actors with the precise intelligence needed to execute such targeted crimes.
Future Outlook
Affected users are now warned to be vigilant against phishing attempts arriving via email, SMS, phone calls, and even physical mail. Because the attackers know the victims are Trezor users, these scams are likely to be highly convincing and tailored to the product. Security experts suggest that users remain skeptical of any unsolicited communication requesting sensitive information or directing them to external links, regardless of the medium used.