Trezor confirmed Thursday that a breach at one of its shipping partners exposed personal data on 13,689 customers. Names, home addresses, phone numbers and email addresses were taken.
No crypto moved. Trezor says its own systems, its devices and customer wallet backups were never touched. The damage sits with an outside vendor.
What the Trezor Data Breach Exposed
ShipMonk stores and ships Trezor orders. On August 10, it told Trezor that an intruder had reached systems holding customer records.
The exposure splits in two. Some 11,742 buyers lost everything, meaning name, email, phone number and full shipping address. Another 1,947 lost only a name, city and email.
Timing decides who is caught. The leak covers orders delivered between May 10 and Aug. 8 this year in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
Older buyers were spared by a rule. Trezor makes partners delete or anonymize order data 90 days after delivery, so earlier shipments were already wiped.
There is one simple test. Affected customers received an email from [email protected]. No email means no exposure.
One detail stings. ShipMonk holds SOC 2 Type II certification, an audited security standard, and was breached anyway.
Why a Leaked Address Beats a Leaked Email
An email alone buys a scammer little. A name, a home address and a phone number together do far more. They mark a specific person at a specific door as a crypto buyer.
Trezor spelled out the playbook. Scammers can send fake emails, place fake calls, mail fraudulent letters, or pose as a bank, an exchange, or Trezor itself.
That pattern has history. Ledger lost roughly 1 million customer emails in July 2020. Some 9,500 of those buyers also had full postal details exposed, and fake recovery phrase letters reached their homes years later.
Now compare the scale. Trezor’s breach exposed complete addresses for 11,742 people, more than the 9,500 Ledger buyers hit in 2020.
Ledger CEO Pascal Gauthier answered the same fear in 2020, and the logic still holds.
“there is no way to make any correlation between the data that has leaked and the funds on your wallet,” read an excerpt in the Ledger announcement.
Attackers already had the brand in view. A recent Trezor phishing ad appeared days before this disclosure. Separately, fake support call scams have drained millions from holders this year.
Vendors keep proving to be the weak link. Ledger’s payment processor breach leaked customer order data in January.
What Trezor Owners Should Do Now
The advice is short and it works. Treat urgency as a red flag. Check anything odd against Trezor’s official channels. Never type a wallet backup into a website.
“Never enter your wallet backup on a website or share it with anyone,” Trezor wrote in a blog.
Two habits reduce future exposure. Order with an email that is not tied to your real name, and pay in crypto where possible.
Trezor also promised an Anonymous Delivery option built on locker pickup and neutral packaging. It targets the EU by September and the US by the end of 2026.
Trezor says this is the first breach since 2013 to expose customer phone numbers and shipping addresses. The hardware still holds. The weak point was never the device. It was the box it arrived in.









