Trezor Data Breach Exposes Personal Information of Nearly 14,000 Customers

SECURITY PRODUCT

Hardware wallet manufacturer Trezor has disclosed a data breach at one of its third party shipping providers, exposing the personal information of nearly 14,000 customers.

Trezor said the incident occurred at ShipMonk, a logistics provider responsible for fulfilling Trezor orders in several countries. ShipMonk notified Trezor on August 10 that its systems had been accessed without authorization. The investigation remains ongoing.

According to Trezor, 11,742 customers experienced full exposure, including their names, email addresses, phone numbers and shipping addresses. Another 1,947 customers experienced partial exposure, involving their name, city and email address.

The affected countries include the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

Trezor devices remain secure

Trezor emphasized that the breach did not compromise its own systems, products or services. Private keys and wallet backups were not exposed, and the company said its devices remain secure.

However, the leaked information could make affected customers targets for more sophisticated phishing and social engineering attacks. Scammers could use the exposed names, addresses and phone numbers to impersonate Trezor, banks, cryptocurrency exchanges or other trusted organizations.

Trezor has contacted affected customers directly by email and advised them to be especially cautious about unexpected emails, phone calls, letters and websites requesting personal information.

The company has also reiterated that users should never enter their wallet backup or recovery seed online or share it with anyone.

Why was the breach limited?

Trezor said its 90 day data retention policy helped limit the amount of information available to the attacker. The company requires fulfillment partners to delete or anonymize customer order data after 90 days.

Trezor initially said the affected orders were those received between May 10 and August 8, 2026. However, the company has since noted that the 1,947 customers whose exposure was limited to their name, city and email address may include older orders. Trezor said it is still verifying the exact timeframe with ShipMonk.

The company said this is the first breach since Trezor was founded in 2013 that exposed customer phone numbers and shipping addresses.

Trezor introduces more private ordering options

Following the incident, Trezor also outlined several ways customers can reduce the amount of personal information shared when purchasing hardware wallets.

The company recommends using an email address that is not connected to a person’s real identity, paying with cryptocurrency where possible, and using a P.O. Box for delivery where available.

Trezor also announced an upcoming Anonymous Delivery option, which is expected to launch in the European Union by September 2026 and the United States by the end of 2026. The service is intended to provide more private delivery through options such as locker pickup, neutral packaging and automatic deletion of shipping identifiers after delivery.

The incident serves as a reminder that Bitcoin security extends beyond the wallet itself. Even when private keys and devices remain secure, personal information collected during the purchase and delivery of hardware wallets can create another avenue for attackers.

Source: Trezor official breach announcement

ENJOYED THIS ARTICLE?Support the authorSend a zap over Lightning or on-chain