Independent Reviews
Plain sealed cardboard parcel on a dark wooden bench
Data Breach Published 15 Aug 2026 5 min read2 sources

Trezor Customers Exposed in ShipMonk Shipping-Provider Breach

Names and contact details for 13,689 customers were exposed through a fulfilment partner, creating targeted crypto-phishing risk even though Trezor says its wallets remain secure.

By VPN Rocks Editorial Team

The short version

What you need to know

  • Trezor says a breach at fulfilment partner ShipMonk exposed details for 13,689 customers, including 11,742 records with names, emails, phone numbers and full shipping addresses.
  • Trezor says its own systems and hardware wallets were not compromised. The immediate risk is personalised phishing by email, phone or post, not automatic theft from the device.
  • Never type a wallet backup into a website or share it with anyone. A VPN cannot erase exposed order records, authenticate a message or protect a recovery seed voluntarily disclosed to a scammer.

What happened at the shipping provider?

Trezor said on 12 August that ShipMonk, a third-party fulfilment and shipping provider, had discovered unauthorised access to systems containing customer order data. ShipMonk notified Trezor on 10 August, and the investigation into the precise timeline and scope was still continuing.

Trezor identified 13,689 affected customers. For 11,742 people, the exposed fields included name, email address, phone number and shipping address. Another 1,947 records contained name, city and email address. Order numbers may also have been present in delivery records.

What was not compromised

Trezor says its own infrastructure, products and services were not breached and that customer hardware wallets remain secure. The incident therefore does not mean an affected device needs to be replaced or its wallet automatically moved.

The distinction matters because a convincing scam may falsely claim that the physical wallet is now unsafe. The exposed contact and delivery data can identify someone as a likely hardware-wallet owner, but it does not reveal the wallet backup or give an attacker direct control of crypto assets.

What affected customers should do

Trezor says it separately emailed every affected customer from help@trezor.io. Verify any notice against Trezor's official incident post and support route rather than replying, calling a supplied number or using a link in an unexpected follow-up. Be alert to tailored email, phone and postal approaches that mention a name, address, order or wallet purchase.

Never reveal a wallet backup, seed phrase, PIN, password or authentication code. Never enter the backup on a website, app, computer or phone, even if a message claims that migration, verification or emergency recovery is required. Follow Trezor's official instructions and enter it only through the hardware wallet's own on-device recovery process.

Where a VPN helps — and where it does not

A VPN can encrypt internet traffic on an untrusted network and reduce what a local observer learns. It could also hide a usual public IP address from many websites, but it cannot retrieve customer data already copied from a supplier or remove a home address from an exposed record.

It cannot authenticate an email, phone call, letter or wallet-support website, and it cannot protect funds after a user discloses a recovery phrase. Independent verification, strict control of the wallet backup and scepticism toward urgent contact are the relevant safeguards.

VPN Rocks view

Shipping data is unusually sensitive in the hardware-wallet context because it connects a real-world identity and address with probable crypto ownership. Even without financial credentials, that combination can make social engineering more specific and more believable.

The incident also shows why data minimisation at suppliers matters. Trezor says its 90-day deletion or anonymisation requirement limited the exposure, although it was still checking whether some partially exposed older orders sat outside the expected period. Retention promises need technical enforcement and verification across every partner holding the data.

Primary reading

Sources and further reading

We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.

Useful next steps