Key Takeaways
- ShipMonk, Trezor’s logistics partner, experienced unauthorized system access affecting approximately 14,000 users
- Leaked information includes customer names, contact emails, telephone numbers, and mailing addresses
- No compromise to Trezor’s internal infrastructure or hardware wallet security
- Users in seven countriesâUS, UK, Sweden, Colombia, Brazil, Italy, and Portugalâface heightened phishing threats
- First instance in Trezor’s 13-year operation where phone numbers and physical addresses were compromised
Hardware cryptocurrency wallet manufacturer Trezor has issued an alert to approximately 14,000 users following a security incident at ShipMonk, its third-party logistics provider, which resulted in the exposure of customer information.
The security event was disclosed on August 13, 2026. According to Trezor’s statement, 11,742 users had their complete personal details accessed, including full names, contact emails, telephone numbers, and complete shipping addresses. An additional 1,947 individuals had partial data exposed, limited to names, cities, and email contacts.
Impact and Affected Users
Individuals who ordered Trezor hardware between May 10 and August 8 in seven nationsâthe United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugalâmay be vulnerable. Those who purchased via Amazon marketplace remain unaffected, as Amazon orders utilize a different logistics provider.
Trezor has directly contacted all compromised users via email. The company emphasized that those who did not receive direct communication were not part of this incident.
The company stressed that its core infrastructure remained untouched. “Your Trezor device is secure,” the firm stated. Customer risk stems primarily from potential social engineering attacks.
Malicious actors may exploit the exposed data to masquerade as Trezor representatives, financial institutions, or cryptocurrency platforms through fraudulent emails, telephone scams, or physical mail schemes. Users should maintain skepticism toward any unsolicited communications purporting to be from Trezor.
Escalating Risks for Cryptocurrency Owners
Data compromise incidents are accelerating worldwide. Cybersecurity provider SentinelOne reports a 17% surge in breaches during 2026 versus the previous year, with approximately 2,090 incidents recorded globally each week.
After stolen information enters underground markets, criminals exploit it for extended periods. Extortion schemes have utilized home addresses to extract ransoms ranging from $700 to $1,000, with some perpetrators shipping counterfeit hardware devices to targets.
Physical coercion targeting crypto asset holders is intensifying. According to blockchain security provider Certik, in-person robbery and extortion attacks reached $124 million during the first six months of 2026.
Trezor emphasized this represents the initial occurrence across its 13-year operational history where customer telephone contacts and physical mailing addresses were exposed. Earlier security events in 2024 and 2022 impacted support system users and email databases, but excluded shipping information.
Trezor’s proprietary firmware and device-level security protocols have never experienced remote exploitation resulting in fund theft.
Competing hardware wallet manufacturer Ledger experienced a comparable third-party data exposure in January 2026, connected to its e-commerce partner. A 2020 Ledger breach impacted nearly 300,000 individuals, subsequently leading to scammers distributing counterfeit devices to victims.
Trezor has verified that no compromised information has been publicly released, traded on dark web marketplaces, or deployed in confirmed fraud attempts related to this breach at this time.





