ADVERTISEMENT

Events

IAMTN Annual Summit 2026
14 Oct 26
London
Money20/20 USA 2026
18 Oct 26
Las Vegas

Trezor Confirms ShipMonk Breach Exposed Data of Nearly 14,000 Customers

Trezor has confirmed that a data breach at ShipMonk, the third-party fulfillment provider that ships Trezor Shop orders in several markets, exposed personal information belonging to roughly 13,689 customers. The hardware wallet maker told DeFi Planet its own systems, devices, private keys, and wallet backups were not affected.

According to a blog post published August 13, ShipMonk informed Trezor of unauthorized access to its systems on Monday, August 10. The breach exposed full names, physical addresses, phone numbers, and email addresses for 11,742 customers, while a further 1,947 customers had a smaller set of data exposed, limited to name, city, and email address.

The exposure covers customers who received a trezor.io order in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal between May 10 and August 8, 2026. Trezor said all affected customers were notified directly by email from help@trezor.io, and that anyone who did not receive that email is not affected.

The breach traces back to a third-party analytics tool

Trezor’s own statement does not disclose how ShipMonk’s systems were compromised. But breach notification emails ShipMonk sent to affected customers, reviewed by BleepingComputer, point to a vulnerability in Metabase, a third-party analytics platform ShipMonk used internally. Metabase told ShipMonk on August 6 that an unauthorized party had exploited a vulnerability in its software to access account and customer data. Metabase has separately disclosed that attackers exploited a critical SQL injection zero-day to gain administrator access to customer instances of its platform, a campaign that also hit laptop maker Framework and form-builder Tally.

BleepingComputer also reported that ShipMonk has received extortion emails from the ShinyHunters group, a threat actor associated with several high-profile data theft campaigns. Trezor has not commented on the extortion attempt.

Trezor’s 90-day retention policy limited the exposure

Trezor attributed the breach’s limited scope to its data retention policy, which requires that order data be deleted or anonymized 90 days after delivery, a requirement Trezor also imposes on fulfillment partners. Without that policy, Trezor said, the exposure could have covered years of order history rather than a three-month window.

Trezor said it has notified the relevant data protection authority and remains in contact with ShipMonk to establish the full scope of the incident. The company has not said whether it will continue working with ShipMonk once the investigation concludes, though it has confirmed ShipMonk has since secured the affected systems and hardened its security.

INTERESTING: Crypto Isn’t Perfect, But It’s the Best Shot We’ve Got at Rewriting Finance 

Phishing is the primary risk, not wallet compromise

Trezor emphasized that the breach did not touch its own infrastructure and that hardware wallets, private keys, and wallet backups remain secure. The company said the main risk to affected customers is an increase in more targeted phishing attempts by email, phone, or post, since attackers now have verified proof that specific individuals own a hardware wallet along with the address it was delivered to. Trezor reiterated that it will never ask a customer for their wallet backup, and urged affected customers to treat any unsolicited request for personal or wallet information as suspicious, even if it appears to reference real order details.

This is the first breach in Trezor’s history, the company was founded in 2013, that has exposed customer phone numbers and shipping addresses. Trezor disclosed a separate breach in January 2024 after attackers accessed its third-party support ticketing portal. Rival hardware wallet maker Ledger experienced a comparable shipping-related data breach in 2020, after which some affected customers were targeted with fake replacement devices designed to compromise their funds.

Trezor plans a more private shipping option

Trezor said it is developing an “Anonymous Delivery” option intended to reduce the amount of personal data collected during checkout, including a dedicated checkout flow, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery. 

The company said it aims to launch the option in the EU by September 2026 and in the US by the end of 2026. In the meantime, Trezor’s blog post recommends customers use an email address not linked to their real identity when ordering, consider paying with crypto or a disposable virtual card, and use a P.O. box where possible to limit address exposure.

 

FAQs

How many Trezor customers were affected by the ShipMonk breach

Approximately 13,689 customers were affected. Of these, 11,742 had their full name, phone number, email address, and shipping address exposed, while 1,947 had a smaller set exposed, limited to name, city, and email.

Were Trezor devices or wallet backups compromised

No. Trezor said its own systems, hardware wallets, private keys, and wallet backups were not affected. The breach occurred at ShipMonk, a third-party shipping provider, not at Trezor.

How do I know if I was affected

Trezor emailed every affected customer directly from help@trezor.io. If that email is not in your inbox, Trezor says you were not affected.

 

 

Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights

Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

ADVERTISEMENT
ADVERTISEMENT

Spotlight

-
00:00
00:00
Update Required Flash plugin
-
00:00
00:00