Briefly
- A breach at ShipMonk, one in every of Trezor’s success companions, uncovered private knowledge belonging to 13,689 Trezor prospects.
- Full names, telephone numbers, e-mail addresses and transport addresses have been taken for 11,742 of them.
- Trezor says no machine, personal key or pockets backup was affected, and that its programs weren’t compromised.
A knowledge breach at one in every of Trezor’s transport suppliers has uncovered the names, telephone numbers, e-mail addresses and residential addresses of 1000’s of the {hardware} pockets producer’s prospects, the corporate disclosed on Thursday.
ShipMonk, which shops and ships Trezor’s merchandise, informed the corporate on Monday that an unauthorized get together had reached programs holding buyer knowledge. Some 11,742 prospects had their full particulars taken and one other 1,947 had names, cities and e-mail addresses uncovered, a complete of 13,689. These affected positioned orders between Might 10 and August 8 and had them shipped to the US, United Kingdom, Sweden, Colombia, Brazil, Italy or Portugal.
We’ve got some troublesome information to share. Sadly, one in every of our transport suppliers has skilled an information breach that uncovered delicate order knowledge. This impacts new prospects within the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who acquired an order throughout the 90 days…
— Trezor (@Trezor) August 13, 2026
Trezor mentioned its personal programs weren’t compromised and that no machine, personal key or pockets backup was touched. It attributed the restricted scope to a coverage requiring companions to delete or anonymize order knowledge 90 days after supply, which meant older orders have been now not held. Clients who didn’t obtain a notification e-mail will not be affected, it mentioned. In 13 years, the corporate added, it has by no means earlier than had a breach exposing buyer telephone numbers and transport addresses.
Phishing and “wrench assaults”
Trezor’s warning issues phishing, and it advises prospects to deal with sudden contact with suspicion and by no means to enter a pockets backup on-line. The 2020 precedent at rival Ledger suggests the chance runs additional than fraudulent e-mail.
After roughly 272,000 Ledger prospects had names, addresses and telephone numbers printed, some started receiving ransom calls for threatening violence. One informed Decrypt they acquired a number of emails and texts a day, whereas others later reported receiving phishing calls from individuals who spoke as if they knew them.
These threats now have extra firm, with CertiK verifying 52 bodily assaults on crypto holders worldwide within the first half of 2026, up from 39 a yr earlier, and residential invasions overtaking kidnapping as the commonest methodology. Chainalysis put the sum stolen at greater than $30 million over the identical interval and mentioned the yr was heading in the right direction to be the worst on report.
This is not the primary such incident to strike on the vendor chain for {hardware} wallets. Ledger disclosed a breach at its personal e-commerce companion, World-e, in January, and {hardware} pockets corporations warned of a phishing surge this month as losses from the Coldcard exploit approached $130 million.
The information lands as {hardware} pockets customers have been rocked by the current Coldcard exploit. A few of the 233,000 BTC that left long-term holder wallets across the Coldcard breach, price roughly $15 billion, got here from Ledger and Trezor homeowners fairly than Coldcard prospects, transferring to multi-signature setups after watching the exploit unfold, in accordance with Casa.
Trezor mentioned it’s bringing ahead an Nameless Supply possibility utilizing locker pickup, impartial packaging, generic sender particulars and automated deletion of transport identifiers, focusing on the European Union by September and the US by the tip of the yr.
Every day Debrief E-newsletter
Begin every single day with the highest information tales proper now, plus authentic options, a podcast, movies and extra.

