
Trezor has warned nearly 14,000 customers after its fulfillment partner, ShipMonk, experienced unauthorized access that exposed sensitive order information.
The incident is the first breach involving Trezor customers in which shipping addresses were exposed.
According to Trezor, the names, email addresses, phone numbers and shipping addresses of 11,742 customers were compromised. Data from another 1,947 customers, including names, cities and email addresses, was also affected. The impacted customers are located in the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal.
Trezor disclosed the incident Thursday, saying a shipping provider had suffered a breach that exposed customer order details.
The attack comes as data breaches continue to rise worldwide. Cybersecurity firm SentinelOne said breaches have increased 17% from 2025, with an average of 2,090 incidents occurring globally each week. The company also estimated that breaches have been increasing by about 3% month over month since January.
Trezor said it contacted all affected customers by email and confirmed that those who did not receive a notification were not impacted. The company also told CoinDesk that it has not found evidence that the stolen information has been published, shared or sold.
So far, Trezor has not identified any scams or hacking attempts connected to the incident. Customers who purchased through Amazon were not affected because those orders are processed by a different fulfillment provider.
Trezor Wallets Remain Secure
Trezor stressed that its own systems were not compromised and that its hardware wallets remain secure. The breach did not give attackers direct access to customers’ cryptocurrency.
Instead, the main concern is the possibility of targeted phishing and social-engineering attacks. Criminals could use the exposed contact and shipping details to impersonate Trezor, banks or cryptocurrency exchanges through emails, phone calls or physical mail.
Information stolen during a data breach can remain useful to criminals for years. Leaked shipping records can be reused in later fraud attempts, phishing campaigns and other targeted attacks.
In some cases, attackers have used leaked home addresses to demand ransoms of $700 to $1,000 or send counterfeit hardware devices directly to victims. Companies can also face substantial legal, recovery and reputational costs following major customer data exposures.
Crypto holders face physical security risks as well. CertiK reported that in-person coercion attacks involving crypto users totaled $124 million during the first half of the year, although not all were linked to data breaches. DeepStrike estimates that data breaches cause tens of billions of dollars in losses globally each year.
Trezor Has Faced Previous Data Breaches
Trezor said the latest incident marks the first time in its 13-year history that customer phone numbers and shipping addresses have been exposed.
However, the company has previously experienced breaches involving third-party services. Satoshi Labs, Trezor’s parent company, disclosed a security incident affecting a third-party support portal in January 2024, exposing information belonging to 66,000 people. Another breach in April 2022 compromised data from 106,856 Trezor customers.
Despite these incidents, Trezor said its internal firmware and on-device cryptographic protections have never been remotely breached to steal users’ funds.
Ledger, another major hardware wallet provider, has also experienced third-party breaches. A January incident involved its e-commerce partner Global-e, while a 2020 breach affected nearly 300,000 Ledger users. In 2021, scammers used information from that incident in a follow-up phishing campaign involving fake Ledger devices.





