Nearly 14,000 people who bought a Trezor hardware wallet this summer now have their names and home addresses sitting in the hands of an unknown attacker — a list that identifies them, by address, as crypto holders.
Trezor disclosed on August 13 that ShipMonk, the third-party fulfilment provider that warehouses and ships its products, reported unauthorised access to systems holding customer order data on Monday, August 10. The investigation is ongoing.
What Data Was Exposed
11,742 customers had full records exposed: full name, email address, phone number and shipping address. A further 1,947 had partial exposure limited to name, city and email — 13,689 in total. ShipMonk also stores order numbers, which lets an attacker reference a real purchase in a phishing message.
Trezor says its own systems, firmware and devices were untouched. No private keys, wallet backups or funds were involved, and operations continue normally.
Which Orders Are Affected
Only orders delivered between May 10 and August 8, 2026, to the US, UK, Sweden, Colombia, Brazil, Italy and Portugal. Trezor's 90-day retention rule — which it contractually imposes on fulfilment partners — meant older order data had already been deleted or anonymised, capping the blast radius. Affected customers were emailed directly from [email protected]; no email means no exposure.
Trezor's guidance is framed around phishing. The address field carries a heavier risk. When roughly 272,000 Ledger customer records leaked in 2020, victims reported ransom demands and threats of violence, not just fake emails. CertiK verified 52 physical attacks on crypto holders in the first half of 2026, up from 39 a year earlier, with home invasions overtaking kidnapping as the most common method.
This is also the second hardware-wallet vendor compromised through a commerce partner this year — Ledger disclosed a January 2026 incident at provider Global-e that exposed names, postal addresses, phone numbers and order details. The attack surface is the supply chain, not the device.
Five of the seven affected countries fall under GDPR or UK GDPR, which requires regulator notification within 72 hours; Brazil's LGPD imposes similar duties.
What Affected Customers Should Do
Treat any unsolicited call, letter or email referencing a Trezor order as hostile. Never type a wallet backup into a website. Verify announcements against trezor.io directly. Consider a mail-forwarding address for future hardware deliveries — Trezor's promised Anonymous Delivery option is not live yet, targeting the EU by September 2026 and the US by year-end.