Trezor customer addresses exposed in breach at shipping contractor ShipMonk
Trezor says a breach at logistics contractor ShipMonk exposed names and contact details of roughly 13,700 customers, including home addresses and phone numbers for 11,742 of them.
About 13,700 Trezor customers had personal data exposed after an unauthorized party accessed order records held by ShipMonk, the third-party logistics provider that fulfils the hardware wallet maker's shipments.
Per a Trezor announcement late Wednesday, reported by The Block, ShipMonk notified Trezor on Monday. The larger group — 11,742 customers — had names, email addresses, phone numbers and shipping addresses exposed. A second group of 1,947 had names, cities and email addresses taken. Affected customers span the U.S., UK, Sweden, Colombia, Brazil, Italy and Portugal.
Trezor said its internal systems were not touched and the wallets themselves remain secure — accurate as far as it goes, since seed phrases never leave the device and were never in ShipMonk's systems. The company also said this is the first breach since its 2013 founding to expose customer phone numbers and home addresses.
The immediate risk is impersonation: attackers holding a verified name, phone number and address can pose convincingly as Trezor, a bank or an exchange to extract seed phrases. The longer-tail risk is physical. Ledger's 2020 breach, which exposed data on more than 270,000 customers and ended up on a hacking forum, still generates fraudulent calls and physical letters six years on, per The Block; Ledger had a separate January 2026 exposure via e-commerce vendor Global-e.
Key facts
- 11,742 customers: names, emails, phone numbers, shipping addresses exposed — Trezor announcement, via The Block
- 1,947 customers: names, cities, emails exposed — same
- Total ≈13,689, rounded by The Block to "nearly 14,000"
- ShipMonk notified Trezor Monday, Aug. 10; Trezor disclosed late Wednesday, Aug. 12
- Countries affected: U.S., UK, Sweden, Colombia, Brazil, Italy, Portugal — Trezor
- More than $30 million stolen in violent crypto attacks in H1 2026, against $58 million for all of 2025 — Chainalysis, cited by The Block
The real-world read
The disclosure is notably thin on the parts that matter operationally. It doesn't say when the intrusion happened, how long the attacker had access, how they got in, whether the access is closed, or what ShipMonk is doing about it. ShipMonk itself has issued no public statement in evidence here.
"Hardware wallets remain secure" and "first time since 2013" are both true statements that also do useful framing work: they steer toward Trezor's product integrity and away from the fact that Trezor chose the vendor now leaking its customers' home addresses. The "first" claim is self-reported and not independently checkable.
Two secondhand items warrant a caveat. The Chainalysis run-rate — $30 million in half a year "on pace" to beat $58 million — is a projection, not an outcome, and Chainalysis sells compliance tooling into exactly this threat narrative. And the French home-invasion case The Block references comes from local reporting it relays without naming the outlet; it involves leaked tax data, not this breach.
Also worth noting: The Block discloses that Foresight Ventures, which invests across crypto, is its majority investor. Trezor is not a stated holding.
Opinion, and whose
Trezor's position, in its own announcement, is that wallet security is unaffected. The Block's Kyle Baird argues phishing is the lesser hazard when home addresses are involved, given rising physical coercion attacks — a judgment, not a finding.
Sources
- The Block (Kyle Baird), Aug. 13 — victim counts, data categories, notification timeline, country list, direct quote from Trezor's announcement, Ledger precedent, Chainalysis figures. Secondary; Trezor's announcement is the primary document underneath it. Not sponsored; ownership disclosure noted above.
- Trezor announcement, Aug. 12 — quoted via The Block; not read directly here.
Not financial advice.