Trezor customers exposed after shipping partner ShipMonk is hacked

Roughly 13,700 buyers of the hardware wallet had names, addresses and phone numbers stolen through a third-party logistics breach.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A warehouse or logistics facility with packages being processed on conveyor systems, security breach notification on nearby computer screen, shipping labels and
Share

Key points

  • Trezor, which makes hardware wallets for storing cryptocurrency, disclosed a breach affecting nearly 14,000 customers.
  • The break-in happened at ShipMonk, the logistics company that ships Trezor orders, not at Trezor itself.
  • 11,742 customers had full details exposed (name, email, phone, shipping address) and 1,947 had partial details exposed (name, city, email).
  • Buyers in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal who ordered between 10 May and 8 August 2026 are affected.
  • Trezor devices and funds are not at risk, but affected customers should expect targeted phishing emails, calls and letters.

Trezor, a Czech company that sells small devices for storing cryptocurrency offline, has told nearly 14,000 customers their personal details were stolen. The theft didn't happen at Trezor. It happened at ShipMonk, the outside firm Trezor pays to pack and post its orders.

ShipMonk told Trezor on 10 August 2026 that hackers had accessed systems holding customer order data. Four days later, Trezor went public. The affected customers placed orders between 10 May and 8 August 2026 across seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

What exactly was stolen?

Order and delivery data, not passwords or crypto keys. For 11,742 customers the hackers took the full set: name, email address, phone number and shipping address. A further 1,947 had a smaller subset taken: name, city and email.

Detail Figure
Total customers affected ~14,000
Full exposure (name, email, phone, address) 11,742
Partial exposure (name, city, email) 1,947
Order window 10 May to 8 Aug 2026
Countries US, UK, SE, CO, BR, IT, PT

Trezor said its own systems weren't touched and the wallets remain secure. No recovery seeds, the 24-word backup codes that control the money, were involved.

Are customers' crypto funds at risk?

Not directly, but the phishing risk is real. A criminal now knows a named person at a named address owns a hardware wallet. That's a shopping list.

Trezor warned buyers to expect "more sophisticated phishing attempts." Phishing is when criminals send fake messages pretending to be a trusted company, hoping the target hands over passwords or, in this case, that 24-word recovery phrase. Anyone who types that phrase into a website loses their crypto.

The warning isn't theoretical. As BleepingComputer reported, a January 2024 breach of Trezor's support ticketing portal exposed 66,000 users; the attackers then ran phishing campaigns aimed at tricking recipients into surrendering their recovery seeds. The pattern of suppliers becoming the weak link isn't unique to Trezor: we reported a near-identical scenario on 10 August when Valve's European shipping partner CEVA Logistics was hacked.

What should affected customers actually do?

Assume any email, call, text or paper letter claiming to come from Trezor, a bank or a crypto exchange is suspect for the next few months. Two practical rules:

  1. Never type your 24-word recovery seed into anything. Not a website, not an app, not a form a support agent sends you. Trezor will never ask for it.
  2. If a message pressures you to "verify" your wallet or click a link, go to the Trezor website directly by typing the address yourself.

Buyers with full exposure should also watch for fake couriers or letters referencing their real order, since the criminals know what was shipped and where.

Who is ShipMonk?

ShipMonk is a US-based logistics firm that handles warehousing and shipping for online retailers. It hasn't publicly detailed how the attackers got in, how long they had access, or how many other clients were affected. Trezor hasn't said whether ShipMonk will face contractual consequences.

A Trezor spokesperson hadn't responded to press queries at the time of publication, BleepingComputer noted.

This is the second time in under three years that a Trezor supplier, not Trezor itself, has been the weak link. For a company whose entire pitch is keeping crypto safe from online attackers, that pattern's worth watching.

© 2026 Threat Vectr