Trezor data exposed in ShipMonk breach
Trezor said a ShipMonk breach exposed customer order data, including users in Brazil. Its own systems were not affected.
Trezor said a breach at its logistics and shipping provider ShipMonk exposed customer order data, including full names, shipping addresses, phone numbers and email addresses. The company said its systems, products and devices were not compromised.
Trezor said a breach at its logistics and shipping provider ShipMonk exposed customer order information, including full names, shipping addresses, phone numbers and email addresses. The company said the incident may affect new customers who received an order in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal between May 10 and August 8, 2026.
What was the scope of the incident?
According to Trezor's statement, ShipMonk stored data needed to deliver packages, such as name, email address, order number, phone number and shipping address. The company said only orders from the 90 days before August 8, 2026 may have been exposed, due to a 90-day data deletion policy.
CoinDesk reported that the warning reached nearly 14,000 users. In that report, the company said 11,742 customers had full exposure of name, shipping address, email address and phone number, while another 1,947 were partially exposed, with name, city and email address.
| Data | Figure | Source/agency |
|---|---|---|
| Users reached | nearly 14,000 | CoinDesk |
| Customers with full exposure | 11,742 | CoinDesk |
| Customers with partial exposure | 1,947 | CoinDesk |
| Exposure window | 90 days before August 8, 2026 | Trezor |
The regional scope includes customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Bloomberg also said the breach affected users who had received an order within the 90 days before August 8, 2026, including in Brazil.
What did Trezor say about its systems?
The company said the breach stemmed from unauthorized access to ShipMonk systems that contained customer data. It also said its internal investigation is still underway.
Trezor stressed that its own systems, products and services were not affected. According to its statement, no hardware wallets or private keys were compromised. Yahoo News reported the same position and added that devices, private keys and wallet backups were also not affected.
What did the provider explain?
BleepingComputer reported that ShipMonk attributed the incident to an exploited vulnerability in Metabase, the third-party analytics platform it used. According to that report, the flaw has already been patched and active sessions were invalidated. The same outlet said ShipMonk began a detailed technical investigation with outside IT experts.
Protos said Trezor was still gathering information about the incident and that, once it has the full picture, it will decide the future of its relationship with ShipMonk.
CryptoRank added that the company plans to introduce Anonymous Delivery in the European Union in September 2026 and in the United States before the end of the year, as a mitigation measure after the breach.
Sources
- Trezor says 13689 customers hit by data breach at shipping partnerprotos.com· Protos
- Recent customer data exposed in shipping provider incidenttrezor.io· Trezor
- Trezor warns 14,000 users after fulfilment partner suffers data breachcoindesk.com· CoinDesk
- Trezor Customer Data Exposed in Shipping Partner Breachyahoo.com· Yahoo News
- Crypto Firm Trezor Says Data Breach Exposed Thousands of Clientsbloomberg.com· BloombergUnverified URL
- Trezor Data Breach Exposes Shipping Details of 13,689 Customerscryptorank.io· CryptoRank
- Trezor discloses data breach affecting nearly 14,000 customersbleepingcomputer.com· BleepingComputer
- With violent crypto home invasions surging, a data breach exposing over 10,000 Trezor owners puts physical safety on the linecryptorank.io· CryptoRank



