← Back to Home News · GLOBAL

Trezor customer data exposed in ShipMonk shipping-partner breach

Make RegTech.com preferred on Google
Trezor customer data exposed in ShipMonk shipping-partner breach
A breach at Trezor's fulfilment provider ShipMonk exposed the personal data of about 13,689 customers; Trezor says devices, seeds and funds were unaffected.
AI Summary
  • Trezor disclosed that about 13,689 customers' personal data was exposed via a breach at its shipping provider ShipMonk (name, email, phone and shipping address for most of them).
  • No Trezor systems, devices, recovery seeds or customer funds were affected; the exposure is confined to data held by the third-party fulfilment partner.
  • Because home addresses of known wallet owners leaked, the main risks are targeted phishing and personal security; Trezor urges users never to share their wallet backup.
  • Trezor says an "Anonymous Delivery" option is coming (EU by September 2026, US by end 2026) to keep customer identity out of the shipping chain.

Trezor has disclosed that personal data belonging to approximately 13,689 of its customers was exposed through a breach at ShipMonk, one of its shipping providers. In its own statement published on 13 August 2026, the hardware wallet maker said it learned of the unauthorised access on Monday, 10 August 2026, and that the exposure relates to orders shipped between 10 May and 8 August 2026.

The company broke the exposure into two groups: 11,742 customers had full exposure — name, email, phone number and shipping address — while a further 1,947 had partial exposure (name, city and email). Affected customers are located in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.

Crucially, Trezor was emphatic that the breach did not reach the product itself. “Our systems were not compromised, and your Trezor device is secure,” the company wrote, adding that “No Trezor system, product, or service was affected.” No wallet backups, private keys, recovery seeds or funds were exposed; the incident is confined to customer and shipping data held by the third-party logistics partner.

That distinction matters, but it does not make the exposure harmless. With names, email addresses, phone numbers, and, for most of those affected, home shipping addresses now in the wrong hands, the immediate danger is targeted phishing and social engineering. And because the physical addresses of known hardware wallet owners have leaked, there is a heightened personal security dimension, too. 

Trezor’s guidance to users: “Never enter your wallet backup on a website or share it with anyone,” “Be suspicious of any communication that prompts immediate action or asks for personal information,” and “Always cross-reference email and web content with official Trezor communications.”

In response, Trezor pointed to an “Anonymous Delivery” option it says is coming soon, targeting EU availability by September 2026 and the US by the end of 2026, intended to keep customer identity out of the shipping chain in future.

A different failure mode from Coldcard

For readers of RegTech.com, the episode rhymes with but is materially different from the Coldcard firmware incident we covered earlier this month. There, the weakness sat in the device itself: a firmware randomiser flaw that degraded key generation and put funds directly at risk. Here, the device is sound; it is the supply chain around it, a third-party fulfilment provider, that failed.

Taken together, the two cases point to a broader truth for the hardware wallet sector: protecting self-custody customers is no longer only about the security of the device, but also about every vendor that touches a customer’s identity, order, and delivery data. 

For compliance and security teams, that puts third-party/vendor risk management and breach notification obligations squarely back in focus.

Link copied to clipboard
AI Bot
AI Bot
Hi! I'm the RegTech.com assistant. How can I help you today?
Ask me anything — top trending news, latest regulatory changes in the EU, or simply search for topics.