Trezor has reported a leak of customer personal data due to a hack of its logistics partner ShipMonk. The incident affected 13,689 buyers from the USA, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received their orders within 90 days before August 8th.
The hardware cryptocurrency wallet manufacturer emphasized that its own systems and devices were not compromised, but affected users may face more sophisticated phishing attacks.
According to Trezor, the unauthorized access to ShipMonk's systems resulted in the full disclosure of data for 11,742 customers — including name, email address, phone number, and delivery address. An additional 1,947 users suffered a partial data leak: attackers could have obtained their name, city, and email address.
What Data Was Obtained by the Attackers
ShipMonk stored information necessary for delivering Trezor orders, specifically name, address, phone number, email address, and order number. According to the company, the incident is limited by its data retention policy: order information is deleted or anonymized 90 days after delivery.
"This is the first instance since Trezor's founding in 2013 where we have encountered a leak resulting in the disclosure of customer phone numbers and delivery addresses," the company stated.
Trezor separately emphasized that the leak did not affect private keys, wallet recovery seeds, or the devices themselves. However, the obtained information could be used for personalized phishing attacks — via email, phone calls, or postal mail.
The company urged users not to enter their wallet recovery seed on any websites or share it with third parties.
Trezor also reported that all affected customers have received a separate notification from the address help@trezor.io. The company continues to investigate the incident jointly with ShipMonk, which has already secured the affected systems and enhanced their security.
Trezor Prepares Anonymous Delivery
Following the incident, Trezor also discussed its work on an anonymous delivery feature, which is designed to reduce the amount of personal data associated with purchasing a hardware wallet. The company plans to launch it in the EU in September 2026 and in the USA before the end of the year.
The option will include a separate checkout form, the ability to use a pseudonym or identifier, pickup via an automated parcel locker, neutral packaging, and automatic deletion of shipping identifiers after order receipt.
Previously, the Donjon security team at Ledger also investigated a vulnerability in the TROPIC01 chip used in the Trezor Safe 7 hardware wallet. The researchers managed to bypass the signature check using an LFI method, but were unable to gain access to secret data. Trezor emphasized at the time that user funds and their data remained protected.
end-content







