Trezor supplier breach links 11,742 home addresses

by

On Aug. 13, Trezor said a breach at the fulfillment provider ShipMonk exposed customer data for about 13,689 hardware wallet buyers, including the delivery addresses of 11,742 people.

The larger group had their names, email addresses, phone numbers, and shipping addresses exposed, while another 1,947 customers had names, cities, and email addresses compromised. ShipMonk handled the information to fulfill and deliver Trezor orders.

Trezor said its own systems, devices, and services were not breached and that customer wallets remain secure. The exposure instead creates a different risk: linking identifiable people and, in most cases, their home addresses to the purchase of a hardware wallet designed to secure crypto holdings.

Ledger customer data breached including info that leads violent criminals to your door
Related Reading

Ledger customer data breached including info that leads violent criminals to your door

A third-party ecommerce compromise can doxx buyers and sharpen social-engineering attacks even when private keys remain safe.

Jan 6, 2026 · Gino Matos

ShipMonk notified Trezor on Aug. 10 that an unauthorized actor had accessed systems containing customer information, according to the company’s Aug. 13 disclosure.

The 11,742 fully exposed records covered orders received between May 10 and Aug. 8. The additional 1,947 records may include older purchases, and Trezor said it was still working with ShipMonk to determine why those records remained available.

Trezor supplier breach links 11,742 home addressesTrezor said its fulfillment partners are generally required to delete or anonymize order information within 90 days of delivery, thereby limiting how much recent customer data remains accessible after an order is completed.

Shipping data can turn a digital breach into a physical-security risk

While the exposed records do not provide access to wallets or private keys, they can make phishing and other attacks substantially more targeted.

Trezor warned that scammers could use the information to impersonate the company, banks, or crypto exchanges through convincing emails, phone calls, and letters. An attacker who already knows that a person bought a Trezor device can tailor a message around wallet security, compromised funds, or supposed account problems rather than relying on generic phishing tactics.

Hardware wallet users rattled by rise in phishing emails pointing to fake Tezor website
Related Reading

Hardware wallet users rattled by rise in phishing emails pointing to fake Tezor website

Fears pose as stark reminder to stay vigilant when clicking links on emails related to digital assets.

Oct 27, 2023 · Oluwapelumi Adejumo

The inclusion of delivery addresses raises a more serious concern because it can identify households associated with people who are likely to own crypto.

That does not mean the ShipMonk data has been used for physical attacks. However, previous cases show how customer databases can help criminals identify potential crypto holders before moving from online reconnaissance to real-world targeting.

In a 2025 case unrelated to Trezor, the US Justice Department described an alleged crypto-theft network that used stolen databases to identify victims and included residential burglars targeting hardware-wallet owners.

Home invasion stalked $4.3M crypto wallet: How a single data leak can put anyone’s safety at risk
Related Reading

Home invasion stalked $4.3M crypto wallet: How a single data leak can put anyone’s safety at risk

Sheffield Crown Court sentenced a trio on Nov. 18, police say nearly the full haul was seized. We break down the “delivery driver” ruse, and how to harden your setup.

Nov 23, 2025 · Gino Matos

Chainalysis has also found that the annual value stolen through violent crypto attacks reached a record $58 million in 2025, with another $30 million stolen by the middle of 2026. Home invasions accounted for 37% of recorded incidents this year, up from 26% in 2023.

Crypto Wrench Attacks
Crypto Wrench Attacks (Source: Chainalysis)

The blockchain analytics firm said attackers range from criminals who send stolen assets directly to centralized exchanges to more sophisticated groups using laundering infrastructure to obscure the proceeds.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.