Data Breaches

← Breach overview
Trezor logo

Trezor

trezor.io
Services & Utilities

Trezor is a hardware wallet manufacturer based in the Czech Republic. It specializes in devices for storing cryptocurrency.

Key Takeaways

  • In August 2026, a data exposure at Trezor's shipping provider, ShipMonk, affected approximately 14,000 customers, revealing names, email addresses, phone numbers and, for many customers, shipping addresses.
  • The leak links confirmed Trezor hardware-wallet purchases to real-world identities and shipping addresses. That creates a physical-security risk beyond phishing, including possible targeting for burglary, coercion or so-called wrench attacks.
  • Trezor said its own systems, devices and wallet backups were not compromised, but the exposed customer data still deserves urgent attention because crypto-related physical attacks have been growing.

Breach Overview

In August 2026, Trezor confirmed a data exposure affecting 13,689 customers. This incident occurred at ShipMonk, a third-party shipping provider used by Trezor. The exposed data included names, email addresses, phone numbers and physical addresses for 11,742 customers. An additional 1,947 customers had their names, cities and email addresses exposed. The affected orders were placed between May 10 and August 8, 2026, and involved customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Because the data is connected to confirmed hardware-wallet orders, the risk is not limited to phishing: a leaked home address can help attackers identify and physically target crypto holders. Trezor stated that its own systems, devices and wallet backups were not affected.

Exposed Data

Email addressesNamesPhone numbersPhysical addresses

Timeline & Cause

The data exposure occurred at ShipMonk after unauthorized access to systems holding Trezor customer order data. ShipMonk informed Trezor on August 10, 2026, and Trezor disclosed the incident on August 12, 2026. Trezor attributed the limited scope of the incident to a 90-day data-retention policy at ShipMonk.

Next Steps

Treat unexpected emails, calls, letters and delivery messages about your Trezor order as potentially hostile. Do not share your wallet backup, PIN or passphrase, and never move funds because someone claims to be Trezor support. Verify messages through Trezor's official website rather than links or phone numbers in the message.

This leak also creates a physical-security risk: it identifies people who bought a hardware wallet and, for many customers, where it was delivered. Crypto-related home invasions, kidnappings and other wrench attacks have been growing, so avoid publicly linking your identity, home address or social accounts to your holdings. If you receive a credible physical threat or see suspicious activity around your home, contact local emergency services and do not confront anyone yourself. Trezor has stated that affected customers were contacted directly about the incident.

Take Action