Trezor ShipMonk Data Breach
Analysis based on 13 articles · First reported Aug 13, 2026 · Last updated Aug 14, 2026
The breach raises concerns about customer privacy and security in the cryptocurrency hardware wallet industry, potentially impacting Trezor's reputation and customer trust. Competitors like Ledger may see a relative benefit, while the incident highlights supply chain vulnerabilities, possibly affecting logistics and cybersecurity sectors.
Trezor, a hardware wallet manufacturer, disclosed a data breach at its fulfillment partner ShipMonk on August 13, 2026. ShipMonk notified Trezor on August 10 that an unauthorized party accessed systems containing customer order data. The breach exposed personal information of 13,689 customers who received orders between May 10 and August 8, 2026, across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Of these, 11,742 had full names, email addresses, phone numbers, and shipping addresses exposed, while 1,947 had partial exposure. Trezor's own systems and hardware wallets were not compromised, and no private keys or funds were at risk. The breach was limited by Trezor's 90-day data retention policy, which required ShipMonk to delete or anonymize order data after 90 days. Trezor warned affected customers of increased phishing risks, as the leaked data could link cryptocurrency ownership to real-world identities and locations. This is the first time Trezor has experienced a breach exposing customer phone numbers and shipping addresses since its founding in 2013. Trezor is also accelerating its Anonymous Delivery option, planned for the EU in September and the US by end of 2026, to reduce such risks.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard