13,689 Trezor Customers Caught Up in Data Leak at Third-Party Shipping Partner

13 689 trezor customers caught up in data leak at third party shipping In Brief:

In Brief:

  • A breach at Trezor’s fulfilment partner ShipMonk hit 13,689 of the wallet maker’s customers.
  • Exposed records included customers’ full names, delivery addresses and phone numbers, raising the odds of targeted phishing.
  • An Anonymous Delivery option is slated to arrive before the close of 2026 as a privacy safeguard.

Breach Details

Trezor has acknowledged a data breach originating with ShipMonk that touched 13,689 of its customers. Dated August 10, 2026, the incident laid bare order details such as full names, shipping addresses and phone numbers.

Full exposure applied to 11,742 of those customers, while the remaining 1,947 saw only partial data revealed. The affected buyers are spread across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal, and the compromised records span orders placed between May 10 and August 8, 2026. Everyone caught up in the leak has been contacted by email.

Scope of the Breach

According to Trezor, nothing on its own infrastructure was touched — hardware wallets and private keys are unaffected. What leaked was strictly fulfilment information, with no cryptographic material involved.

A 90-day data deletion policy already in place limited how much information was sitting there to be taken. With older orders long since wiped, the fallout was restricted to a narrow window instead of Trezor’s full order history. It is the first time in the company’s history that customer phone numbers and addresses have been exposed.

Phishing Risks

What should worry those affected most is a likely wave of phishing. A list of confirmed hardware wallet owners is exactly the kind of material that fuels polished social engineering.

The company’s guidance is straightforward: wallet backups should never be shared with anyone, and any message claiming to come from Trezor should be checked through official channels. There is also a physical angle — leaked shipping addresses can be turned into believable postal mail schemes, a tactic already seen in earlier hardware wallet scams.

Future Enhancements

Trezor used the disclosure to point to Anonymous Delivery, a privacy feature it has in the pipeline. Due in the European Union by September 2026 and in the United States by the end of 2026, it will ship orders in neutral packaging and strip shipping identifiers, severing the link between a buyer’s identity and their hardware wallet purchase.

Implications for Web3 Gaming

No gaming assets were touched by this leak, but the episode still carries a lesson for Web3 gaming. Anyone sitting on NFTs or token rewards is exposed to much the same risk profile as hardware wallet users.

Leaks can spring from anywhere in the stack — guilds, marketplaces and everything in between. Wherever an identity gets tied to on-chain holdings, an attack surface is created.

The defence hasn’t changed: a seed phrase is never something a legitimate service will request, and players should confirm any message through official channels instead of trusting links dropped into suspicious messages.