Skip to main content
Emerging ThreatsData Breaches

Trezor Breach Exposes 13,000 Customers' Personal Data

Boxes and parcels on a warehouse shelf, some open with contents exposed.

More than 13,000 Trezor customers had personal data exposed after a breach at the company's logistics partner, the wallet maker confirmed on August 14, 2026.

Scope and timeline of the exposure

Trezor's initial analysis found the compromise affected orders placed in certain countries during the previous 90 days, but further review expanded the potential window. The company says the breach exposed the names, email addresses, phone numbers, and shipping addresses of 11,742 customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who ordered Trezor products between May 10 and August 8. An additional 1,947 customers had their names, home cities, and email addresses exposed; some members of that group "may have placed their orders before May 10." Trezor said it is "verifying this information and the timeframe with ShipMonk."

ShipMonk's role and Trezor's retention rule

ShipMonk is identified by Trezor as its logistics partner: it "stores and ships products on the company's behalf and collects the information needed to fulfill orders." Trezor says ShipMonk is subject to a 90-day retention policy that "requires partners to delete or anonymize customer data within 90 days of collecting it for an order." The company added that ShipMonk did not immediately respond to a request for comment.

Customer risk: phishing and direct guidance from Trezor

While Trezor reassured customers that "its own systems and devices remain secure," the company warned that "affected customers could experience an increase in phishing attempts." Trezor noted the exposed details could help criminals craft convincing phishing attempts impersonating banks, crypto exchanges, or Trezor itself. The company said it has contacted affected customers directly and advised them to "check any communications against information published through its official channels." In an apologetic advisory Trezor reminded users: "Never enter your wallet backup on a website or share it with anyone."

Trezor's Anonymous Delivery plan

As a direct response to the incident, Trezor said its "top priority" is launching an "Anonymous Delivery" option. According to the company, the service will let buyers complete checkout without linking their home address or real-world identity to an order. Customers using Anonymous Delivery will use a dedicated checkout, supply a nickname or label ID instead of a real name, and have products shipped to an automated delivery locker instead of a home address. Deliveries will arrive in unbranded packaging with a generic sender label, and the carrier will only use email or SMS to send a PIN for the locker. Trezor said the service is gearing up for a September launch in the EU and deployment in the US by the end of the year.

Rival reaction and marketplace chatter

Not all competitors kept silent. Cake Wallet, a rival crypto wallet, "Xeeted": "Another rough day for self custody," and suggested crypto holders instead use an old smartphone with Cake Wallet installed because "there is no order, no shipping address, or customer data tied to the purchase." The remark was a public jibe at Trezor's logistical exposure and the customer-data vector it revealed.

What this means for technologists, affected customers, and logistics partners

  • Technologists and security teams: The breach highlights the dependence of device security on third-party logistics practices; Trezor's note that its systems and devices remain secure focuses attention on customer-facing data flows rather than device-level compromise.
  • Affected customers and self-custody users: Trezor has contacted those it identified and warned of increased phishing risk; its concrete advice includes verifying communications against official channels and the blunt instruction: "Never enter your wallet backup on a website or share it with anyone."
  • Logistics and e-commerce teams: Trezor's 90-day retention policy and the promise of an Anonymous Delivery option underline two levers logistics partners and merchants may need to manage—data retention rules and fulfillment options that reduce the link between a customer's identity and a delivery address.

Trezor framed the incident as unprecedented for the company: "This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses." The firm expressed regret—"We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected"—and has set a specific product and operational response in motion. Meanwhile, the overlap between logistics data and security risk has moved from theoretical to tangible for more than 13,000 customers, and the company and its partner ShipMonk are left to resolve the remaining questions about timing and scope.

Read the original report: https://www.theregister.com/security/2026/08/14/crypto-wallet-maker-trezor-confirms-13000-customers-details-exposed-in-logistics-breach/5287734