Trezor customers exposed after shipping partner ShipMonk is hacked
Roughly 13,700 buyers of the hardware wallet had names, addresses and phone numbers stolen through a third-party logistics breach.

Key points
- Trezor, which makes hardware wallets for storing cryptocurrency, disclosed a breach on 14 August 2026 affecting 13,689 customers.
- The break-in happened at ShipMonk, the logistics company that ships Trezor orders, not at Trezor itself.
- 11,742 customers had full details exposed (name, email, phone, shipping address) and 1,947 had partial details exposed (name, city, email).
- Buyers in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal who ordered between 10 May and 8 August 2026 are affected.
- Trezor devices and funds are not at risk, but affected customers should expect targeted phishing emails, calls and letters.
Trezor, a Czech company that sells small devices for storing cryptocurrency offline, has told nearly 14,000 customers their personal details were stolen. The theft did not happen at Trezor. It happened at ShipMonk, the outside firm Trezor pays to pack and post its orders.
ShipMonk told Trezor on 10 August 2026 that hackers had got into systems holding customer order data. Four days later, Trezor went public.
The stolen data covers people who bought a Trezor wallet between 10 May and 8 August 2026 in seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
What exactly was stolen?
Order and delivery information, not passwords or crypto keys. For 11,742 customers the hackers took the full set: name, email address, phone number and home shipping address. For another 1,947 they took a smaller set: name, city and email.
| Detail | Figure |
|---|---|
| Total customers affected | 13,689 |
| Full exposure (name, email, phone, address) | 11,742 |
| Partial exposure (name, city, email) | 1,947 |
| Order window | 10 May to 8 Aug 2026 |
| Countries | US, UK, SE, CO, BR, IT, PT |
Trezor said its own systems were not touched and the wallets themselves remain secure. No recovery seeds, the 24-word backup codes that control the money, were involved.
Are customers' crypto funds at risk?
Not directly, but the phishing risk is real. A criminal now knows a named person at a named address owns a hardware wallet. That is a shopping list.
Trezor warned buyers to expect "more sophisticated phishing attempts." Phishing is when criminals send fake messages pretending to be a trusted company, hoping the target hands over passwords or, in this case, that 24-word recovery phrase. Anyone who types that phrase into a website loses their crypto.
The warning is not theoretical. As BleepingComputer first reported, a January 2024 breach of Trezor's support ticket system exposed 66,000 users, and the attackers used those details to run phishing attacks aimed at tricking people into surrendering their recovery seeds.
What should affected customers actually do?
Assume any email, text, phone call or even paper letter claiming to come from Trezor, a bank or a crypto exchange is suspect for the next few months. Two practical rules:
- Never type your 24-word recovery seed into anything. Not a website, not an app, not a form a support agent sends you. Trezor will never ask for it.
- If a message pressures you to "verify" your wallet or click a link, go to the Trezor website directly by typing the address yourself.
Buyers with full exposure should also be alert to fake couriers or letters referencing their real order, since the criminals know what was shipped and where.
Who is ShipMonk?
ShipMonk is a US-based logistics firm that handles warehousing and shipping for online retailers. It has not publicly detailed how the attackers got in, how long they had access, or how many of its other clients were touched. Trezor has not said whether ShipMonk will face contractual consequences.
A Trezor spokesperson had not responded to press queries at the time of publication.
This is the second time in under three years that a Trezor supplier, not Trezor itself, has been the weak link. For a company whose entire pitch is keeping crypto safe from online attackers, the pattern is awkward.



