Trezor Data Breach: All You Need to Know

Trezor's shipping partner ShipMonk was hacked, exposing data of 13,689 customers. Here's what leaked, who's affected, and how to stay safe.
Soumen Datta
August 15, 2026
Table of Contents
Trezor, the hardware wallet maker, confirmed that a breach at its shipping partner ShipMonk exposed the personal data of 13,689 customers, including names, phone numbers, email addresses, and home addresses.
Trezor says its own systems, devices, and private keys were not touched, but the leaked contact details put affected buyers at higher risk of phishing.
What Happened In The Trezor Data Breach?
On Monday, August 10, 2026, ShipMonk, one of Trezor's logistics providers, told Trezor that an unauthorized party had accessed systems holding customer order data. Trezor disclosed the incident publicly in a blog post published that Thursday.
The company said the breach affects new customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received an order between May 10 and August 8, 2026.
What Information Was Exposed?
ShipMonk stores the details needed to ship a parcel, such as a customer's name, address, phone number, and email. Trezor broke the exposure down into two groups:
- 11,742 customers had full exposure: full name, shipping address, phone number, and email address.
- 1,947 customers had partial exposure: name, city, and email address only.
Why Was The Breach Limited To 13,689 Customers?
Trezor enforces a 90-day data retention policy and requires fulfillment partners to follow the same rule. Any order data older than 90 days had already been deleted or anonymized before the breach occurred, which is why the exposure stopped at roughly 13,700 people instead of covering Trezor's full customer history.
How Did The ShipMonk Breach Happen?
ShipMonk told affected customers that attackers exploited a vulnerability in Metabase, a third-party analytics platform it uses. Metabase said the vulnerability was a critical SQL injection zero-day that let attackers gain administrator access to customer instances and steal data. The same Metabase flaw also hit laptop maker Framework and online form builder Tally. According to reporting from BleepingComputer, ShipMonk has also received extortion emails from the ShinyHunters group.
Is This Trezor's First Data Breach?
No. Trezor disclosed an earlier breach in January 2024, when attackers accessed its third-party support ticketing portal. That incident exposed the names, usernames, and email addresses of around 66,000 users who had contacted Trezor Support since December 2021.
Attackers later used that stolen data to run phishing attacks that tried to trick people into revealing their 24-word recovery seed.
What Should Affected Trezor Customers Do?
Trezor emailed every exposed customer directly from help@trezor.io. If that email is not in your inbox, your data was not part of this breach. The main risk now is phishing, not device security.
Discover Promising Projects...
Promising Projects...
(Advertisement)
Protect Yourself From Phishing
- Be suspicious of any message that demands urgent action or asks for personal details.
- Check emails and websites against Trezor's official blog and social channels.
- Never type your wallet backup (seed phrase) into a website or share it with anyone.
Order More Privately In The Future
- Use an email address not linked to your real identity when ordering.
- Pay with crypto or a disposable digital card instead of a regular credit card.
- Use a P.O. Box where possible to limit address exposure.
Trezor also announced an upcoming Anonymous Delivery option, which will use a dedicated checkout, locker pickup, neutral packaging, and generic sender details, then delete shipping identifiers after delivery. It's expected in the EU by September 2026 and in the US by the end of 2026.
Conclusion
The Trezor data breach exposed the names, addresses, phone numbers, and emails of 13,689 customers after its shipping partner ShipMonk was hacked through a Metabase vulnerability. Trezor's devices and systems remain secure, its 90-day data retention policy limited the scope of the leak, and the company is rolling out an Anonymous Delivery option to reduce future exposure.
Resources
Report by Trezor: Recent customer data exposed in shipping provider incident
Report by BleepingComputer: Trezor discloses data breach affecting nearly 14,000 customers
Read Next...
Frequently Asked Questions
Disclaimer
Disclaimer: The views expressed in this article do not necessarily represent the views of BSCN. The information provided in this article is for educational and entertainment purposes only and should not be construed as investment advice, or advice of any kind. BSCN assumes no responsibility for any investment decisions made based on the information provided in this article. If you believe that the article should be amended, please reach out to the BSCN team by emailing info@bsc.news.
Author
Soumen DattaSoumen has been a crypto researcher since 2020 and holds a master’s in Physics. His writing and research has been published by publications such as CryptoSlate and DailyCoin, as well as BSCN. His areas of focus include Bitcoin, DeFi, and high-potential altcoins like Ethereum, Solana, XRP, and Chainlink. He combines analytical depth with journalistic clarity to deliver insights for both newcomers and seasoned crypto readers.
Crypto Project & Token Reviews
Project & Token Reviews
Comprehensive reviews of crypto's most interesting projects and assets
Learn about the hottest projects and tokens
Latest Crypto Articles
Get up to date with the latest crypto news stories and events





















