X users' reactions to the Trezor data breach
Cryptocurrency

Trezor Data Breach: Logistics Partner ShipMonk Exposed Data of 14,000 Customers

A security breach at logistics partner ShipMonk has exposed the personal data of nearly 14,000 Trezor customers. While hardware wallets remain secure, users are warned about an increased risk of targeted phishing attacks.

August 14, 2026
3 min read
53 views
O

Ondřej Kadlec

A security incident at logistics partner ShipMonk exposed the personal data of a portion of Trezor customers. Approximately 13,689 people who received an order within the 90 days prior to August 8, 2026, were reportedly affected. Trezor stated that its own systems and hardware wallets were not compromised.

The leak affects customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. The company reported the incident on August 13 after ShipMonk alerted it on August 10 to unauthorized access to systems containing order data.

We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days… — Trezor (@Trezor) August 13, 2026

What exactly was leaked and who is affected?

The total number of affected individuals reaches 13,689 customers, with data exposure varying by group:

  • 11,742 customers: Full name, email, phone number, and shipping address.
  • 1,947 customers: Name, city, and email address.

Trezor stated that customers who did not receive an email notification are not affected. The incident also does not involve orders placed via Amazon, as those are handled by a different partner. The scope of the leak was limited by a policy requiring Trezor's partners to delete or anonymize order data after 90 days. Therefore, older orders should no longer have been stored in ShipMonk's systems.

Wallets remain secure, phishing is the main risk

Trezor emphasized that the leak did not affect devices, private keys, or wallet backups. This is not a breach of hardware wallets or access to funds stored in cryptocurrencies. The risk lies primarily in the fact that personal data can help scammers craft more convincing messages, phone calls, or letters.

X users
X users' reactions were not long in coming. Source: x.com/@0xbags

Attackers may impersonate Trezor, a cryptocurrency exchange, or a bank and try to solicit sensitive information. Trezor has therefore issued strict warnings to its customers:

  • Never enter your wallet backup (seed phrase) on any website.
  • Never share your seed phrase with anyone.
  • Verify all updates and instructions exclusively through the company's official channels.

This is a sensitive type of leak because it combines email or phone numbers with shipping addresses. Trezor stated that since its inception in 2013, it has not experienced an incident where customers' phone numbers and shipping addresses were exposed.

#Data Leak#Security