Nearly 14,000 Trezor customers had personal information exposed after an unauthorized party accessed systems operated by ShipMonk, the hardware wallet maker’s shipping provider, creating a new phishing and physical-security risk for people whose orders can now be linked to their contact details and home addresses.
Trezor said ShipMonk notified it of the incident on Monday, and the company disclosed the breach in a blog post late Wednesday. The exposure did not involve Trezor’s internal systems, firmware, wallets, or customers’ crypto holdings, according to the company. Yet the data held by a delivery provider is highly sensitive in the hardware-wallet market because it can identify people likely to own digital assets.
The company said 11,742 customers had their names, email addresses, phone numbers and shipping addresses exposed. Another 1,947 customers had their names, cities and email addresses included in the incident, putting the total affected population at roughly 13,700.
Trezor said affected customers were located in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. It described the incident as the first since its 2013 founding to expose customer phone numbers and shipping addresses.
Delivery records create a phishing target list
The leaked data could give fraudsters the raw material for highly tailored impersonation attempts. An attacker who knows a person bought a Trezor device, where it was delivered and how to reach them can craft messages that appear to relate to a recent shipment, account security warning, refund, replacement device or firmware update.
Hardware-wallet users should expect any unsolicited communication referencing an order, delivery address, wallet security issue or urgent account action to be treated cautiously. Trezor and other wallet providers do not need a customer’s recovery seed phrase, private keys or PIN to provide support.
A recovery seed phrase is the sequence of words that controls access to a wallet’s funds. Anyone who obtains it can restore the wallet elsewhere and move the assets without possessing the physical device. Fraudsters often seek those phrases through fake support pages, phone calls and messages directing recipients to enter their words into a fraudulent form.
Accurate address and telephone information makes those tactics more credible. A scammer can cite a real shipping destination, claim a package was intercepted, or use the customer’s name in a call purportedly from Trezor, a delivery firm, bank or law-enforcement agency.
Customers affected by the ShipMonk incident should enter Trezor’s website directly into a browser rather than following links in emails or text messages. They should independently verify support requests through official channels and enable phishing-resistant multi-factor authentication, such as a physical security key, on their primary email account where available. Email security deserves particular attention because password-reset links often provide an entry point into financial and crypto-related accounts.
Hardware-wallet makers have faced third-party data leaks before
Trezor’s disclosure recalls a series of data-security failures involving rival hardware-wallet maker Ledger and external service providers. In January, Ledger customers were alerted that names and contact information had been exposed following unauthorized access to order data held by Global-e, a third-party e-commerce provider.
The industry’s most consequential example remains Ledger’s 2020 e-commerce and marketing data breach. Information related to more than 270,000 customers was exposed after attackers accessed data that included names, email addresses, telephone numbers and, in some cases, physical addresses. The information later appeared on a hacking forum.
That breach was followed by phishing operations and reports from customers who received threatening messages, fraudulent calls and physical letters designed to pressure them into surrendering recovery phrases. Alerts tied to the incident persisted for years, demonstrating that customer data can remain useful to criminals long after the initial disclosure.
The pattern places particular pressure on wallet companies to scrutinize logistics, marketing and online retail partners that collect personally identifiable information. A hardware wallet can be designed to keep private keys offline, but its purchaser may be exposed through databases used for shipping, payment support and customer communications.
Address exposure raises offline concerns
The risks are not confined to inboxes and mobile phones. A shipping address can be combined with public social-media activity, past data leaks or information from other online sources to identify people perceived to have substantial crypto holdings.
Reports of physical coercion and home-invasion attempts against cryptocurrency holders have added urgency to those concerns. Recent reporting described a French couple who faced three home invasions in less than a month after moving into a property formerly owned by crypto millionaires whose tax information and address had appeared online.
Chainalysis data cited in recent reporting found that more than $30 million had been stolen through violent attacks in the first half of 2026. That figure approaches more than half of the $58 million reported for all of 2025, although such estimates cover a small and difficult-to-measure category of crypto crime.
Most people affected by a customer-data leak will not face an in-person threat. The more immediate danger is a flood of convincing social engineering messages. Even so, users who publicly discuss wallet holdings or show expensive crypto-related purchases online may wish to review what identifying information they have made available.
For future deliveries, some customers may consider using a post office box or commercial mail-receiving service where practical. They should also avoid publishing photos that reveal home addresses, shipment labels or identifiable details about their wallet setup.
Trezor’s case shows how the security perimeter around self-custody extends beyond the device itself. The hardware wallet may remain technically secure, but a compromised delivery database can give criminals enough personal context to target its owner with greater precision.
Worried about phishing after this breach? Learn key defenses in our guide 5 ways to improve crypto safety today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
