Hardware cryptocurrency wallet manufacturer Trezor has reported an incident involving a data leak of customer information at one of its logistics partners, ShipMonk. Trezor's official account on social network X confirmed the same figures and countries on August 13, 2026.
On August 10, 2026, ShipMonk notified Trezor about unauthorized access to its systems, where customer order data was stored. As a result, the personal data of approximately 13,689 customers was compromised in the leak.
What specific data fell into the wrong hands
The scale of the leak varies depending on the customer:
- For 11,742 people, the full names, email addresses, phone numbers, and delivery addresses were exposed to unauthorized parties;
- For 1,947 customers, only their name, city, and email were leaked—without the full delivery address.
According to updated information from Trezor, some orders with partial data leakage may date back to earlier periods—the company is clarifying the details jointly with ShipMonk.
Geographic scope and timeline of the incident
The incident concerns orders placed in the USA, UK, Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and August 8, 2026. The extent of the leak was limited by Trezor's data retention policy: the company's partners are obligated to delete or anonymize order information 90 days after delivery.
Trezor's own systems were not compromised—users' hardware wallets and cryptocurrency remain secure. All affected customers have already received individual email notifications from help@trezor.io. If such an email was not received, that specific individual's data was not part of the leak.
Risk of phishing attacks
Trezor warns of an increased likelihood of phishing: attackers may use the stolen contact information to send fake emails, calls, or messages purporting to be from Trezor, banks, or crypto exchanges, requesting confirmation of a seed phrase or asking them to click on phishing links. The company emphasizes that a wallet's recovery seed phrase must never be entered on third-party websites or disclosed to anyone.
Anonymous Delivery as a response to the incident
In the same message on X, Trezor discussed its work on the Anonymous Delivery feature—anonymous delivery using nicknames, parcel lockers, neutral packaging, and automatic deletion of identifiers after order delivery. The launch of this option in the European Union is planned for September 2026, and in the USA by the end of 2026.
No public statements from ShipMonk itself regarding the incident had appeared on its official website at the time of checking.
The incident affected nearly 14,000 Trezor customers across seven countries but was limited to delivery data—seed phrases and wallet contents were not affected by the leak. The company is already working to reduce such risks in the future by anonymizing logistics data.
AI Perspective
From the perspective of machine data analysis, the Trezor and ShipMonk incident fits into a persistent pattern in the industry: logistics contractors often store order data longer than necessary for delivery and become a weak link in the supply chain. The hardware wallet market has already experienced a similar scenario—in 2020, Ledger reported a data leak through an e-commerce partner, after which affected customers were plagued by phishing emails and fraudulent calls for months. A technical aspect remaining off-camera in the article: the persistence of such leaks over time—even deleted data "resurfaces" if the contractor's backups are not synchronized with the manufacturer's retention policy. An open question remains: Are hardware wallets, as a product class, even capable of avoiding dependence on external logistics, or does anonymizing delivery merely shift the risk to the next weak link in the chain?
end-content





