Key Points
- ShipMonk, Trezor’s third-party fulfillment provider, experienced unauthorized system access affecting nearly 14,000 customer records
- Exposed information includes customer names, email contacts, telephone numbers, and physical delivery addresses
- Trezor’s internal infrastructure and device security remain uncompromised
- Users in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal face elevated phishing threat levels
- This marks the first time in Trezor’s 13-year operating history that customer telephone numbers and physical addresses have been compromised
Leading cryptocurrency hardware wallet manufacturer Trezor has issued an alert to approximately 14,000 users following a security incident at ShipMonk, its third-party logistics provider, which resulted in the exposure of customer personal information.
The security incident came to light on August 13, 2026. According to Trezor’s disclosure, personal details belonging to 11,742 usersāincluding full names, email contacts, telephone numbers, and complete shipping addressesāwere accessed without authorization. An additional 1,947 users had their names, city locations, and email addresses exposed during the incident.
Impacted Customer Base
Users who received Trezor hardware devices during the period from May 10 through August 8 in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal may be affected by this exposure. Customers who made purchases via Amazon remain unaffected, as those transactions are processed through a different logistics provider.
According to Trezor, all potentially impacted users have been contacted via email. The company confirmed that users who did not receive a direct notification were not involved in the breach.
The company emphasized that its internal security infrastructure remained intact throughout the incident. “Your Trezor device is secure,” the manufacturer stated. The primary concern for affected customers involves potential phishing and social engineering attempts.
Cybercriminals may leverage the compromised information to conduct fraudulent outreach campaigns impersonating Trezor, financial institutions, or cryptocurrency platforms through deceptive emails, phone communications, or physical mail. Users should exercise heightened vigilance regarding any unsolicited communications purporting to originate from Trezor.
Escalating Security Risks in the Crypto Sector
Data security incidents continue to surge worldwide. Cybersecurity analytics from SentinelOne indicate that breaches have climbed 17% in 2026 versus the previous year, with approximately 2,090 cyberattacks documented globally on a weekly basis.
Stolen personal data typically circulates on illicit marketplaces for extended periods. Threat actors have utilized residential addresses to execute extortion schemes demanding payments ranging from $700 to $1,000, and some incidents have involved fraudulent hardware devices sent through postal services to targeted victims.
Physical confrontation attacks targeting cryptocurrency holders are also on the rise. Blockchain security analyst Certik reported that in-person coercion incidents accounted for $124 million in losses during the initial six months of 2026.
Trezor emphasized that this represents the inaugural occasion in its 13-year operational timeline where customer telephone contacts and residential addresses have been compromised in a security breach. Earlier incidents occurring in 2024 and 2022 impacted support system users and email databases, but did not involve physical delivery information.
The company’s proprietary firmware and device-level security protocols have maintained a flawless record against remote exploitation attempts targeting user funds.
Competing hardware wallet provider Ledger experienced a comparable third-party vendor breach in January 2026, connected to its e-commerce infrastructure partner. A 2020 Ledger security incident impacted nearly 300,000 users, with subsequent reports of fraudsters distributing counterfeit devices to those affected individuals.
Trezor has verified that no compromised data from this incident has been publicly released, traded on underground markets, or utilized in fraudulent schemes to date.


