Close Menu
Crypto Valley Journal
    Facebook X (Twitter) Instagram
    Crypto Valley Journal
    • Hot Topics
      • News
      • Minds
    • Focus
      • Background
      • Blockchain
      • Legal & Compliance
      • Non-Fungible Token (NFTs)
    • Investing
      • Markets
      • Financial Products
      • Decentralized Finance (DeFi)
      • Exchange overview
    • Education
      • Basics
      • Glossary
      • Politicians on crypto
    • Statistics
      • Bitcoin-ETF-Flows
      • Ethereum-ETF-Flows
      • Crypto market data
      • On-chain data
    • Academy
      • Overview
      • Part 1: Blockchain
      • Part 2: Money
      • Part 3: Bitcoin
      • Part 4: Cryptocurrencies
      • Part 5: Decentralized Finance
      • Part 6: Investing
    • English
      • Deutsch
    Crypto Valley Journal
    You are at:Home » Hot Topics » News » Trezor data breach at shipping partner exposes customer data
    The Trezor data breach at fulfillment provider ShipMonk exposed names, addresses and phone numbers of 13,689 customers.

    Trezor data breach at shipping partner exposes customer data

    By Editorial Office CVJ.CH on 14. August 2026 News

    An unauthorised third party accessed customer data at Trezor's fulfillment partner. The Trezor data breach affects 13,689 customers across seven countries. For 11,742 of them, the exposure covers full name, delivery address, phone number and email address.

    Trezor is a hardware wallet brand owned by the Czech company SatoshiLabs. The devices store private keys offline, separated from the internet. As a result, they count among the safest forms of self-custody. That same security focus makes the customer list valuable, because anyone on it very likely holds crypto. The incident covers orders from the period between 10 May and 8 August 2026. Shipments went to the US, the UK, Sweden, Colombia, Brazil, Italy and Portugal. The service provider involved is ShipMonk. However, devices, private keys and wallet backups remained untouched according to the company. In response, the manufacturer also announced an anonymous shipping option.

    Subscribe to our newsletter

    The best articles of the week, directly delivered into your mailbox.

    What the Trezor data breach at ShipMonk exposed

    ShipMonk informed Trezor on 11 August 2026 about the unauthorised access to systems holding customer data. Since Trezor sells its devices online, external partners handle delivery. Fulfillment providers handle storage, picking and shipping. Therefore they need full delivery addresses and contact details of end customers. Without those details, no parcel gets delivered. Exactly this data set lay exposed. Two days later, the company went public with the case.

    The affected customers fall into two groups. For 11,742 customers the exposure is complete, including name, delivery address, phone number and email address. For another 1,947, it is limited to name, city and email address. Both groups thus make up the reported 13,689 cases. Names and phone numbers enable targeted phishing calls, while the delivery address makes the holder physically locatable. According to the company, the access covered neither devices nor private keys or wallet backups. Trezor's own systems likewise stayed out of the attacker's reach. Overall, the incident hits the logistics layer around the product.

    The manufacturer attributes the limited scope to a strict 90-day data retention policy. It applies contractually to fulfillment partners as well. Older order data no longer exists there. Earlier shipments consequently fall outside the affected period. Trezor also notified every affected customer separately by email. Moreover, the company apologised publicly for the incident. The investigation continues, and updates are to appear on the company blog.

    Why an address list puts crypto holders at particular risk

    A buyer list for hardware wallets is not an ordinary customer base. Anyone who links a home address to a Trezor purchase therefore identifies a probable target. That buyer very likely holds larger crypto holdings. The precedent dates from 2020. At competitor Ledger, attackers took around 1.1 million email addresses through a third-party interface. Additionally, they obtained roughly 272,000 detailed records with full name, phone number and postal address. In December 2020, that data eventually ended up publicly online. Soon after, broad phishing and extortion campaigns hit Ledger customers, in some cases with threats to their physical safety. Ledger later addressed the incident in a public statement.

    The threat landscape has worsened since then. Chainalysis counted 46 violent crypto-related incidents worldwide in the first half of 2026. A year earlier the count stood at 40. These so-called wrench attacks include kidnappings, home invasions and hostage takings. Perpetrators seized around USD 30 million in the first half of the year alone. In total, they attempted to obtain USD 107 million. According to Chainalysis, that puts 2026 on track to break the 2025 record. That full-year record stood at USD 58 million. The attackers' success rate, however, fell from 49% in 2025 to 26%. At the same time, the number of attempts is rising while fewer of them succeed.

    Regionally, France stands out. Chainalysis counts 30 publicly known incidents there, while authorities have recorded more than 70. The analytics firm identifies a data breach at the tax administration as one cause. The leak dates to 2024 and affected the greater Paris area. An official allegedly stole and sold records of wealthy crypto owners, including names, addresses, phone numbers and holdings. Criminal groups then used that material to plan their attacks. They picked their targets based on the recorded holdings. Ultimately, the path from an address list to the front door is documented.

    Ray Dalio’s Bridgewater Associates Minds

    Star investor Ray Dalio considers Bitcoin inferior to gold

    Bitcoin overtakes gold in the US: per River's report, 49.6 million Americans own Bitcoin, while just 28.8 million still hold gold. Background

    Bitcoin overtakes gold among US investors for the first time

    Goldman Sachs pays up to USD 2.25 billion for Neos Investments and gains three options income ETFs on Bitcoin and Ethereum. Financial Products

    Goldman Sachs secures three crypto income ETFs with Neos

    What separates Dogecoin from Bitcoin is its unlimited supply, and the 2013 satire coin now trades through its own US spot ETF. Basics

    What is Dogecoin? From satire project to ETF asset

    Ray Dalio’s Bridgewater Associates Minds

    Star investor Ray Dalio considers Bitcoin inferior to gold

    Bitcoin overtakes gold in the US: per River's report, 49.6 million Americans own Bitcoin, while just 28.8 million still hold gold. Background

    Bitcoin overtakes gold among US investors for the first time

    Anonymous delivery as an answer to the address problem

    About an hour after the first notice, Trezor announced an option called "Anonymous Delivery". It targets exactly the data category that lay exposed at ShipMonk. Customers first enter a nickname or a label ID at checkout instead of their real identity. The shipment then goes to an automated parcel station, where buyers collect it themselves. Real name and home address no longer sit together at the service provider. A courier with name and address at the front door disappears.

    In addition, the packaging stays unmarked and carries a generic sender. The provider sends the pickup PIN by email or SMS only. Instead, pickup stations replace the home address as the delivery point. The buyer's real name no longer appears on the shipment. A compromised service provider would consequently give up only pseudonyms and pickup points. Trezor calls the project its current top priority.

    The option should become available in the EU from September 2026. In the US, it is due towards the end of 2026. Until then, orders continue to run through the existing channels. Meanwhile, the timeline shows the limits of the announcement. For the 13,689 customers already affected, the new shipping option changes nothing. Ultimately, the announcement is an admission that shipping data is a security problem in its own right.

    Reporting duties and the pattern behind the incident

    Behind Trezor stands SatoshiLabs, based in the Czech Republic. European data protection law thus applies to the incident. The General Data Protection Regulation requires a report to the supervisory authority within 72 hours. In particular, that duty applies when a breach poses a risk to those affected. Jurisdiction in this case would fall to the Czech supervisory authority ÚOOÚ. Since the deadline starts with knowledge of the breach, the clock began on 11 August 2026. Still, whether and when Trezor filed such a report is not publicly documented.

    The recurrence of the pattern stands out. In all three cases, the data sat outside the systems that crypto users controlled themselves. Previously it was a marketing interface and a tax authority, now a shipping provider. As a result, third-party providers form a recurring attack vector against crypto holders. The cryptography of the devices was never the problem. For buyers, custody security starts at the order. The logistics behind it remain vulnerable.

    Share. Facebook Twitter LinkedIn Email Telegram WhatsApp

    About the author

    Editorial Office CVJ.CH
    • Website
    • Twitter
    • LinkedIn

    Since 2018, the editorial team at Crypto Valley Journal has been reporting from Zug - the heart of Switzerland’s Crypto Valley - on Bitcoin, cryptocurrency, blockchain, and regulatory developments in digital assets. Behind the publication’s collective editorial voice is a team of writers with backgrounds in financial markets, law, and technology.

    Related Articles

    India's central bank confirms early BRICS talks on linking CBDCs, yet no evidence supports a role for the XRP Ledger in the plans.

    BRICS CBDC push puts XRP Ledger in the spotlight

    Strategy sells Bitcoin worth USD 108.6 million, buys back STRC preferred shares and lifts its USD reserve to USD 4.65 billion.

    Strategy sells another 1,690 Bitcoin below its cost basis

    The Bitcoin BIP-110 split left the minority chain at two blocks, while the main chain kept mining and moved 111 blocks ahead.

    Bitcoin split via BIP-110 stalls after two blocks

    The Trezor data breach at fulfillment provider ShipMonk exposed names, addresses and phone numbers of 13,689 customers.
    14. August 2026

    Trezor data breach at shipping partner exposes customer data

    Goldman Sachs pays up to USD 2.25 billion for Neos Investments and gains three options income ETFs on Bitcoin and Ethereum.
    13. August 2026

    Goldman Sachs secures three crypto income ETFs with Neos

    India's central bank confirms early BRICS talks on linking CBDCs, yet no evidence supports a role for the XRP Ledger in the plans.
    13. August 2026

    BRICS CBDC push puts XRP Ledger in the spotlight

    twitter image button instagram image button linkedin image button youtube image button

    About Crypto Valley Journal
    About Crypto Valley Journal

    On the pulse of the movement

    • Academy
    • Contact
    • Advertising
    • About us
    • Partner
    • Imprint
    • Privacy
    • Disclaimer
    Search

    Type above and press Enter to search. Press Esc to cancel.