An unauthorised third party accessed customer data at Trezor's fulfillment partner. The Trezor data breach affects 13,689 customers across seven countries. For 11,742 of them, the exposure covers full name, delivery address, phone number and email address.
Trezor is a hardware wallet brand owned by the Czech company SatoshiLabs. The devices store private keys offline, separated from the internet. As a result, they count among the safest forms of self-custody. That same security focus makes the customer list valuable, because anyone on it very likely holds crypto. The incident covers orders from the period between 10 May and 8 August 2026. Shipments went to the US, the UK, Sweden, Colombia, Brazil, Italy and Portugal. The service provider involved is ShipMonk. However, devices, private keys and wallet backups remained untouched according to the company. In response, the manufacturer also announced an anonymous shipping option.
What the Trezor data breach at ShipMonk exposed
ShipMonk informed Trezor on 11 August 2026 about the unauthorised access to systems holding customer data. Since Trezor sells its devices online, external partners handle delivery. Fulfillment providers handle storage, picking and shipping. Therefore they need full delivery addresses and contact details of end customers. Without those details, no parcel gets delivered. Exactly this data set lay exposed. Two days later, the company went public with the case.
The affected customers fall into two groups. For 11,742 customers the exposure is complete, including name, delivery address, phone number and email address. For another 1,947, it is limited to name, city and email address. Both groups thus make up the reported 13,689 cases. Names and phone numbers enable targeted phishing calls, while the delivery address makes the holder physically locatable. According to the company, the access covered neither devices nor private keys or wallet backups. Trezor's own systems likewise stayed out of the attacker's reach. Overall, the incident hits the logistics layer around the product.
The manufacturer attributes the limited scope to a strict 90-day data retention policy. It applies contractually to fulfillment partners as well. Older order data no longer exists there. Earlier shipments consequently fall outside the affected period. Trezor also notified every affected customer separately by email. Moreover, the company apologised publicly for the incident. The investigation continues, and updates are to appear on the company blog.
Why an address list puts crypto holders at particular risk
A buyer list for hardware wallets is not an ordinary customer base. Anyone who links a home address to a Trezor purchase therefore identifies a probable target. That buyer very likely holds larger crypto holdings. The precedent dates from 2020. At competitor Ledger, attackers took around 1.1 million email addresses through a third-party interface. Additionally, they obtained roughly 272,000 detailed records with full name, phone number and postal address. In December 2020, that data eventually ended up publicly online. Soon after, broad phishing and extortion campaigns hit Ledger customers, in some cases with threats to their physical safety. Ledger later addressed the incident in a public statement.
The threat landscape has worsened since then. Chainalysis counted 46 violent crypto-related incidents worldwide in the first half of 2026. A year earlier the count stood at 40. These so-called wrench attacks include kidnappings, home invasions and hostage takings. Perpetrators seized around USD 30 million in the first half of the year alone. In total, they attempted to obtain USD 107 million. According to Chainalysis, that puts 2026 on track to break the 2025 record. That full-year record stood at USD 58 million. The attackers' success rate, however, fell from 49% in 2025 to 26%. At the same time, the number of attempts is rising while fewer of them succeed.
Regionally, France stands out. Chainalysis counts 30 publicly known incidents there, while authorities have recorded more than 70. The analytics firm identifies a data breach at the tax administration as one cause. The leak dates to 2024 and affected the greater Paris area. An official allegedly stole and sold records of wealthy crypto owners, including names, addresses, phone numbers and holdings. Criminal groups then used that material to plan their attacks. They picked their targets based on the recorded holdings. Ultimately, the path from an address list to the front door is documented.
Anonymous delivery as an answer to the address problem
About an hour after the first notice, Trezor announced an option called "Anonymous Delivery". It targets exactly the data category that lay exposed at ShipMonk. Customers first enter a nickname or a label ID at checkout instead of their real identity. The shipment then goes to an automated parcel station, where buyers collect it themselves. Real name and home address no longer sit together at the service provider. A courier with name and address at the front door disappears.
In addition, the packaging stays unmarked and carries a generic sender. The provider sends the pickup PIN by email or SMS only. Instead, pickup stations replace the home address as the delivery point. The buyer's real name no longer appears on the shipment. A compromised service provider would consequently give up only pseudonyms and pickup points. Trezor calls the project its current top priority.
The option should become available in the EU from September 2026. In the US, it is due towards the end of 2026. Until then, orders continue to run through the existing channels. Meanwhile, the timeline shows the limits of the announcement. For the 13,689 customers already affected, the new shipping option changes nothing. Ultimately, the announcement is an admission that shipping data is a security problem in its own right.
Reporting duties and the pattern behind the incident
Behind Trezor stands SatoshiLabs, based in the Czech Republic. European data protection law thus applies to the incident. The General Data Protection Regulation requires a report to the supervisory authority within 72 hours. In particular, that duty applies when a breach poses a risk to those affected. Jurisdiction in this case would fall to the Czech supervisory authority ÚOOÚ. Since the deadline starts with knowledge of the breach, the clock began on 11 August 2026. Still, whether and when Trezor filed such a report is not publicly documented.
The recurrence of the pattern stands out. In all three cases, the data sat outside the systems that crypto users controlled themselves. Previously it was a marketing interface and a tax authority, now a shipping provider. As a result, third-party providers form a recurring attack vector against crypto holders. The cryptography of the devices was never the problem. For buyers, custody security starts at the order. The logistics behind it remain vulnerable.








