A breach at fulfillment provider ShipMonk exposed names, contact details, and home addresses for thousands of Trezor hardware wallet buyers. Trezor says wallets and funds remain secure, but the leak can help criminals identify households likely to hold crypto.
On Aug. 13, Trezor said a breach at fulfillment provider ShipMonk exposed customer data for about 13,689 hardware wallet buyers, including the delivery addresses of 11,742 people. ShipMonk notified Trezor on Aug. 10 that an unauthorized actor had accessed systems containing customer information.
Trezor said its own systems, devices, and services were not breached and that customer wallets remain secure. But the exposure creates a different risk: linking identifiable people, and in most cases their home addresses, to the purchase of a device built to secure crypto holdings.
What data was exposed
The larger group of 11,742 people had names, email addresses, phone numbers, and shipping addresses exposed, covering orders received between May 10 and Aug 8. Another 1,947 customers had names, cities, and email addresses compromised, a group that may include older purchases. Trezor said it was still working with ShipMonk to determine why those older records remained accessible, noting that fulfillment partners are generally required to delete or anonymize order information within 90 days of delivery.
A digital breach with physical stakes
The exposed records don't reach wallets or private keys, but they can make phishing and other attacks more targeted. Trezor warned that scammers could use the data to impersonate the company, banks, or exchanges through convincing emails, calls, and letters, tailoring messages around wallet security rather than relying on generic phishing.
However, the addresses raise a sharper concern: they can identify households likely to hold crypto. That doesn't mean the ShipMonk data has been used for physical attacks, but similar customer databases have previously helped criminals move from online reconnaissance to real-world targeting. Chainalysis found that the annual value stolen through violent crypto attacks reached a record $58 million in 2025, with another $30 million stolen by the middle of 2026. Home invasions accounted for 37% of recorded incidents this year, up from 26% in 2023.
Industry response and Trezor's fix
Helius co-founder and CEO Mert Mumtaz said breaches involving customer information will keep occurring across software providers, and urged users to reduce personal information shared across services, using separate email aliases, unique passwords, and hardware-based multi-factor authentication instead of SMS. He also argued a hardware wallet alone shouldn't be treated as sufficient protection for substantial holdings, recommending multi-signature setups instead.
Trezor said it plans to introduce Anonymous Delivery in the European Union by September 2026 and in the US by the end of the year, using a dedicated checkout, locker pickup, neutral packaging, and generic sender details, with shipping identifiers deleted after delivery. For affected customers, Trezor advised treating urgent information requests with suspicion, verifying messages through official channels, and never entering a wallet backup into a website.
Source: CryptoSlate
Trading involves risk.