OKX Banner
BTC $62,867.00 (-1.50%)
ETH $1,875.85 (-0.80%)
BNB $605.66 (-1.10%)
XRP $1.00 (-0.90%)
SOL $75.48 (-0.90%)
TRX $0.33 (-0.70%)
HYPE $56.54 (-1.10%)
DOGE $0.07 (-1.30%)
RAIN $0.01 (+4.00%)
LEO $9.23 (-1.80%)
ZEC $488.40 (-1.90%)
XMR $397.74 (-1.80%)
ADA $0.18 (-2.20%)
LINK $8.80 (+1.00%)
XLM $0.16 (-1.50%)
BCH $205.18 (-4.90%)
CC $0.10 (-4.40%)
GRAM $1.32 (-1.50%)
USDG $1.00 (+0.00%)
LTC $44.61 (-0.40%)

Trezor Breach at Shipping Partner Exposes 13,700 Customers' Addresses

Twitter icon  •  Published 3 часа назад on August 14, 2026  •  Hassan Maishera

Nearly 14,000 Trezor customers had names and contact details exposed in a ShipMonk breach, increasing the risk of phishing and physical attacks.

Trezor Breach at Shipping Partner Exposes 13,700 Customers' Addresses

TL;DR

  • Around 13,700 Trezor customers had personal data exposed following a breach at shipping provider ShipMonk.

  • The leaked information included names, email addresses, phone numbers, and shipping addresses.

  • Trezor said its internal systems and hardware wallets were not compromised.

Nearly 14,000 Trezor customers have had their personal information exposed after an unauthorized party accessed order data stored by the hardware wallet manufacturer’s shipping provider, ShipMonk.

ShipMonk informed Trezor of the breach on Monday, according to an announcement published by the wallet company late Wednesday.

Trezor emphasized that the incident did not affect its internal systems or compromise the security of its hardware wallets. However, the exposure of customers’ contact details and home addresses creates potentially serious security risks.

Names, Phone Numbers and Addresses Exposed

The breach affected two groups of Trezor customers. The first and largest group consisted of 11,742 customers whose names, email addresses, phone numbers and shipping addresses were exposed.

Another 1,947 customers had their names, cities, and email addresses compromised. Combined, the two groups bring the estimated number of affected customers to approximately 13,700.

The victims are located across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

Trezor said this was the first security incident since its establishment in 2013 to expose customer phone numbers and shipping addresses.

The company did not indicate that payment information, wallet recovery phrases, private keys or cryptocurrency holdings were compromised.

The breach occurred within ShipMonk’s systems rather than Trezor’s internal infrastructure.

Consequently, the incident does not directly affect the operation or security of customers’ hardware wallets. An attacker cannot access cryptocurrency stored with a Trezor device using only a customer’s name, email address, phone number or physical address.

However, the exposed data can help criminals build convincing social-engineering campaigns.

An attacker could impersonate Trezor, a cryptocurrency exchange, a bank or a security company while referencing the victim’s real name, phone number and purchase history. These details can make fraudulent communications appear legitimate.

Scammers may falsely claim that a wallet has been compromised and instruct the victim to enter a seed phrase into a website, install malicious software or transfer assets to a supposedly secure wallet.

Trezor will never need a customer’s recovery seed to investigate an account or provide support.

Ledger Breaches Demonstrate Long-Term Phishing Risk

Customers of rival hardware wallet manufacturer Ledger have faced similar data exposures.

In January 2026, Ledger customers were informed that names and contact information had been compromised following unauthorized access to order data held by third-party e-commerce provider Global-e.

A significantly larger Ledger breach occurred in 2020, exposing data belonging to more than 270,000 customers. Attackers accessed the company’s marketing and e-commerce records, including names, email addresses, phone numbers and, in some cases, home addresses.

The stolen information was later published on a hacking forum and used in phishing campaigns, harassment and other forms of intimidation.

Six years after the incident, some Ledger customers reportedly continue to receive fraudulent phone calls and physical letters from criminals attempting to obtain their recovery phrases and other sensitive information.

The persistence of these scams shows that compromised customer information can remain valuable to criminals long after the original breach.

Leaked Addresses Create Physical Security Concerns

Phishing is not the only danger associated with exposing hardware wallet purchase records.

Shipping data can potentially reveal that a person owns cryptocurrency and identify where they live. Criminals may use this information to select victims for burglaries, kidnappings, home invasions and physical extortion attacks—sometimes called wrench attacks.

In one recent incident, a couple in France reportedly experienced three home invasions in less than a month after moving into a property previously owned by cryptocurrency millionaires. The former owners’ address and tax information had reportedly appeared on the dark web.

The attackers repeatedly targeted the property even though the intended victims no longer lived there.

Data from Chainalysis found that criminals stole more than $30 million through violent cryptocurrency-related attacks during the first half of 2026. The total is on course to exceed the $58 million recorded throughout 2025.

Trezor customers affected by the ShipMonk breach should treat unsolicited emails, calls, text messages and physical mail with caution.

Users should avoid clicking links in unexpected messages and instead access Trezor services through previously verified bookmarks or by manually entering the company’s official website address.

Customers should never reveal their recovery seed, private keys, PIN, or wallet credentials to anyone. Legitimate Trezor employees will not request this information.

Those whose home addresses were exposed may also want to review their physical security arrangements and avoid publicly discussing the value or location of their cryptocurrency holdings.

 

SEC Abruptly Cancels Meeting on Reg Crypto, Its Crypto Funding Framework
Next article SEC Abruptly Cancels Meeting on Reg Crypto, Its Crypto Funding Framework
Hassan Maishera Senior Reporter

Hassan is a Nigeria-based financial content creator that has invested in many different blockchain projects, including Bitcoin, Ether, Stellar Lumens, Cardano, VeChain and Solana. He currently works as a financial markets and cryptocurrency writer and has contributed to a large number of the leading FX, stock and cryptocurrency blogs in the world.