Trezor reported the data leak of 13,689 customers after an attack on one of its logistics partners. The attackers obtained names and e-mail addresses, and in the case of most of the victims, also telephone numbers and physical shipping addresses. The hardware wallets themselves were not hacked and users’ private keys remain safe. However, the problem is serious for another reason: criminals can now know who bought the hardware wallet, how to contact him, and in some cases also where he lives.
This does not mean that someone took over their bitcoins or other cryptocurrencies. In this case, the greatest risk begins beyond the device itself: from a well-prepared phishing scam, a fake call from “support” or a message that, thanks to the victim’s real data, may look much more credible than a typical scam.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days
trezor.ioRecent customer data exposed in shipping provider incidentShipMonk, one of Trezor’s shipping providers, has experienced a data breach that exposed sensitive customer order data, including full names, physical addresses, phone numbers, and email addresses….
Who is affected by the Trezor data leak?
ShipMonk informed Trezor of unauthorized access to data on August 10, 2026. The incident affects customers who received their Trezor order between May 10 and August 8, 2026 in the USA, Great Britain, Sweden, Colombia, Brazil, Italy or Portugal. Poland is not on the list of countries indicated by Trezorwhich is important information for people who ordered devices directly to a Polish address.
The company contacted those affected by the incident via a message sent from the address help@trezor.io. According to the information she provided, customers who did not receive such a notification were not affected by this particular leak.
The scale of the violation could have been much greater. It was limited by Trezor’s data storage policy towards logistics partners. Information regarding orders is to be deleted or anonymized after 90 days, which is why the attacked system did not contain the full history of the manufacturer’s customers.
Do you have a Trezor? You don’t have to transfer cryptocurrencies
For device owners, the most important information is simple: there is no indication that the security of Trezor’s hardware wallets has been compromised. The company emphasizes that its own systems were not compromised and attackers did not gain access to private keys, wallet backups or data stored on devices.
The leak itself is not a reason to generate a new seed phrase or immediately transfer cryptocurrencies to another wallet. Moreover, an attempt to convince the user that he or she needs to “secure funds” urgently after the incident may be the beginning of the actual attack.
The scenario is easy to imagine. The injured party is called by a person introducing himself as an employee of Trezor. It knows his name, phone number, email address, and perhaps also the address to which the device was shipped. It informs about a real data leak, so the first part of the conversation sounds completely credible. Only later will you be asked to “migrate your wallet”, install a special update, visit a specific website or enter a recovery phrase.
The biggest threat is phishing
An email address alone does not give you access to cryptocurrencies. The situation is much worse when it can be combined with a name, telephone number, physical address and information that the person has purchased equipment for storing digital assets themselves. This set allows you to create phishing attacks tailored to a specific victim, without the typical warning signals associated with mass-sent spam.
Fraudsters don’t have to limit themselves to email. The disclosed information may be used for phone calls, text messages or attempts to impersonate customer service. Messages that refer directly to the current incident may be particularly dangerous: if the user knows from the media that the leak actually took place, it will be easier to believe subsequent instructions allegedly sent by the manufacturer.
For now, Trezor does not report any confirmed cases of theft of funds or physical threats to customers that could be directly linked to the ShipMonk breach. However, this does not change the fact that the disclosed data may remain useful to fraudsters long after the leak itself disappears from the front pages of news websites.
After a leak, someone wants to “secure” your wallet? This is a warning signal
The most important rule remains the same as before the incident: Trezor does not need the user’s seed phrase to provide technical support. You should not give it to a support employee, enter it on a website opened from a link in an e-mail, or forward it to a person contacting you by phone or instant messenger.
You should be especially careful with messages about the need to “migrate your wallet”, “verify your device”, “activate new security measures” or confirm your recovery phrase. Similarly with time pressure: information that the wallet will be blocked in a few hours or that funds must be transferred immediately is a typical social engineering tool. Trezor also reminds that it is not possible to remotely deactivate the user’s device.
After this leak, the meaning of one more rule changes: you should not trust the interlocutor just because he knows your real details. The name, telephone number, e-mail address or delivery address are no longer proof that the device manufacturer is actually on the other side. For some customers, this information could have reached the attackers.
This is not the first leak related to Trezor
Some of the first reports about the case included the statement that this was the first such case in the manufacturer’s history. It requires clarification. Trezor has previously faced an incident involving its users’ data.
The current case is more serious in this respect. According to Trezor, it is the first incident involving his partner in which customers’ phone numbers and physical shipping addresses were also exposed. From the point of view of the cryptocurrency owner, the difference is significant because it allows fraudsters to go beyond classic e-mail phishing.
Hardware wallet can protect the seed. It will not protect the delivery address
The ShipMonk incident draws attention to a weaker point of self-custody, which is much less talked about than securing the seed phrase. The hardware wallet itself may do a great job of isolating private keys from a potentially infected computer, but its purchase is still done through traditional e-commerce and logistics systems.
The store needs to know who is placing the order. The logistics operator must know where to deliver the shipment. Along the way, there are databases, partner systems and courier companies that have nothing to do with the device’s cryptographic security. For people with larger amounts of cryptocurrency, protecting this information may be as practical as choosing the right way to store the seed.
Trezor is already working on changing this model. The company announced a solution enabling the ordering of devices without permanently linking the purchase to the home address and actual identity of the customer. The new option is expected to appear in the European Union in September. Until recently, it may have looked like a feature intended mainly for the most privacy-conscious bitcoiners. After the current incident, its meaning becomes much easier to understand.
What should a Trezor owner do?
However, it is worth assuming that the disclosed information may be used in future fraud attempts and treating every contact regarding the security of the wallet with greater caution. The most dangerous phishing after such an incident does not have to look like phishing. It may be written in correct Polish or English, contain real data of the recipient and refer to an event that actually took place.
So the safety boundary remains where it was before: the seed phrase does not reach support, the online form or the person on the other end of the phone. The Trezor customer data leak didn’t change that. It only made it so that someone trying to extort it from us can now be much better prepared.