Hardware wallet maker Trezor disclosed a data breach exposing personal information of 13,689 customers across seven countries, the company said Thursday.
"Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts," the Prague-based company said in a statement on X.
The breach originated at ShipMonk, Trezor's third-party fulfillment partner, which experienced unauthorized access to systems containing customer order data. Of the affected customers, 11,742 had their names, emails, phone numbers, and shipping addresses exposed, while 1,947 had names, cities, and emails leaked. Orders were delivered between May 10 and August 8 in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
The exposure gives attackers a verified list of crypto hardware wallet owners matched to physical addresses — data that enables targeted phishing, impersonation, and potentially physical attacks. Trezor said it is accelerating an Anonymous Delivery option, targeting EU availability by September 2026 and US availability by the end of 2026.
Trezor's 90-day data retention policy limited the scope of the breach, the company said. ShipMonk has secured the affected systems and hardened its security since the incident, according to SatoshiLabs, Trezor's parent company.
The incident follows a string of security failures across the hardware wallet sector. In 2020, an unauthorized party accessed Ledger's e-commerce database, leaking over 1 million email addresses and personal contact data of nearly 10,000 customers. Ledger's payment partner Global-e suffered a separate data breach in January 2026. More recently, hackers drained $111 million in Bitcoin from Coldcard hardware wallets, with some estimates putting the figure above $130 million.
The physical risk is growing. CertiK verified 52 physical attacks on crypto holders worldwide in the first half of 2026, up from 39 a year earlier, with home invasions overtaking kidnapping as the most common method. Chainalysis put the amount stolen through violent attacks at more than $30 million over the same period.
Trezor said affected customers were contacted directly from [email protected] and urged users to distrust unsolicited communications and never disclose wallet backups. The company also suggested ordering with an email address not linked to a real identity, paying with crypto or a disposable virtual card, and using a P.O. Box where practical.
The breach highlights a structural weakness in the hardware wallet supply chain: the device itself may be secure, but the commercial layer around it — shipping, payment processing, customer support — remains a target. ShipMonk holds SOC 2 Type II certification, an audited security standard, and was breached regardless, according to the company.
This article is for informational purposes only and does not constitute investment advice.