Trezor Discloses Data Breach Affecting Nearly 14,000 Customers

Trezor has built its entire reputation on being the thing that does not get hacked — a physical device your private keys never leave. That reputation held up this month, technically. What did not hold up was the shipping paperwork.
August 10: A Third-Party Provider Gets Breached
ShipMonk, a fulfillment provider Trezor uses to ship hardware wallets to customers, notified Trezor of unauthorized access to its systems. The intrusion exposed order records rather than anything stored on Trezor’s own infrastructure — a distinction Trezor has repeated in every subsequent statement, since it is the difference between a shipping-data leak and an actual compromise of customer crypto holdings.
Who Was Affected, and What Was Exposed
Trezor says the breach affected 13,689 customers total who placed orders within the 90 days before August 8, across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Of that group, 11,742 customers had full names, shipping addresses, phone numbers, and email addresses exposed. A smaller subset of roughly 1,947 customers had a narrower set of data compromised. Trezor has been explicit that no devices, private keys, seed phrases, or funds were accessed — the exposure is limited to personal and shipping information tied to specific orders.
Why This Breach Is Still a Meaningful First
Trezor has operated since 2013 without a customer-data incident of this scale, according to its own disclosure, which is what makes this breach notable even though the core product security was never touched. The specific combination of data exposed — real names, home or business shipping addresses, phone numbers, and emails, all tied directly to the fact that the person owns a hardware crypto wallet — is close to a purpose-built list for targeted phishing and even physical-security risks, since an attacker now knows both who owns meaningful crypto holdings and where to find them.
The Response Industry Peers Are Watching
Reaction from elsewhere in the industry was swift, with competing wallet providers using the moment to remind their own users to stay alert for a wave of Trezor-themed phishing attempts likely to follow.
What Affected Customers Should Actually Do
- Treat any email, text, or call referencing a Trezor order as suspicious by default, even if it includes real details like a name or address — that information is exactly what leaked.
- Never enter a seed phrase or recovery words into a website, app, or support chat, regardless of how official it looks; Trezor and legitimate wallet providers never ask for this.
- Be skeptical of unsolicited “replacement device” or “security update” offers referencing this breach specifically — a known pattern following past hardware-wallet-adjacent leaks.
- Consider that a home address is now plausibly linked to crypto ownership, and weigh physical-security precautions accordingly.
Trezor has said it notified all affected customers individually by email and continues to work with ShipMonk on the underlying investigation. No timeline has been given for when, or whether, ShipMonk will disclose further details of how its systems were accessed.
This article discusses a security incident, not investment products. Always verify wallet and security communications independently; this is not financial advice.
For a refresher on hardware wallet security best practices and seed phrase hygiene, see Coin680’s Bitcoin Academy.
