ShipMonk Breach Puts Nearly 14K Trezor Customers at Phishing Risk
CMC Crypto News

ShipMonk Breach Puts Nearly 14K Trezor Customers at Phishing Risk

3m
1 hour ago

A ShipMonk breach exposed names, addresses, and phone numbers of ~13,700 Trezor customers across 7 countries, as physical crypto attacks climb and hardware wallet incidents multiply in 2026.

ShipMonk Breach Puts Nearly 14K Trezor Customers at Phishing Risk

Índice

Crypto Security News

Trezor disclosed on Aug. 13 that an unauthorized party accessed customer order data held by ShipMonk, the company's third-party fulfillment provider. The breach affected people who ordered Trezor products between May 10 and Aug. 8, 2026, with deliveries going to the US, the UK, Sweden, Colombia, Brazil, Italy, and Portugal. ShipMonk reportedly notified Trezor of the incident on Aug 10.

The numbers break into two groups. A total of 11,742 customers had their full names, email addresses, phone numbers, and home addresses taken. Another 1,947 had their names, cities, and email addresses exposed. Trezor confirmed that its internal systems were not accessed and that no hardware wallet, private key, or wallet backup was touched.

Why the Exposure Was Limited to Recent Orders

Trezor requires fulfillment partners to delete or anonymize customer order data within 90 days of delivery. That policy meant records for older shipments had already been cleared when the breach occurred, containing the exposure to orders placed within the previous three months. Customers who did not receive a direct notification email from Trezor were not affected.

The company called it the first incident in its 13-year history to expose customer phone numbers and shipping addresses. In response, it is accelerating the rollout of an Anonymous Delivery option. That service will route packages through parcel lockers, use neutral packaging, strip sender details, and automatically delete shipping identifiers after delivery. The EU launch is targeted for September 2026, with the US following by the end of the year.

The Real Danger Is Physical, Not Just Digital

Trezor's public warning focused on phishing, advising affected customers to treat any unexpected contact, by email, phone, text, or letter, with suspicion. Attackers holding a person's name, home address, and phone number can build convincing impersonations of Trezor, banks, or crypto exchanges to extract seed phrases or other credentials. But phishing is only part of the risk when home addresses are in the open.

Physical attacks on crypto holders have been accelerating in 2026. Security firm CertiK verified 52 such incidents in the first half of the year, up from 39 over the same period in 2025. Home invasions have overtaken kidnapping as the most common method. Chainalysis put the total amount stolen through violence at more than $30 million during that period, putting the year on course to surpass the $58 million stolen across all of 2025.

Related Article:Coldcard Hack Tops $100M as Galaxy Flags Possible 4th Wave

One case reported on Aug. 13 involved a French couple targeted in three home invasions in less than a month. They had moved into a home previously owned by crypto millionaires whose tax records and address had leaked onto the dark web. The incident underlines how data from breaches at any point in a supply chain can surface in criminal networks long after the initial exposure.

The Trezor disclosure also arrives in a period of heightened concern across the hardware wallet industry. Losses tied to the Coldcard exploit had approached $130 million by the time Trezor made its announcement, and some Bitcoin (BTC) movements traced to Ledger and Trezor owners were linked to users shifting funds into multi-signature setups after watching that breach unfold. In January 2026, Ledger separately disclosed that customer names and contact details had been exposed through a breach at its e-commerce provider Global-e. Ledger's larger 2020 breach, which affected roughly 272,000 customers, showed how persistent the threat can be, with some of those customers still receiving fraudulent physical letters six years later.
This article contains links to third-party websites or other content for information purposes only (“Third-Party Sites”). The Third-Party Sites are not under the control of Vortex, and Vortex is not responsible for the content of any Third-Party Site, including without limitation any link contained in a Third-Party Site, or any changes or updates to a Third-Party Site. Vortex is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement, approval or recommendation by Vortex of the site or any association with its operators. This article is intended to be used and must be used for informational purposes only. It is important to do your own research and analysis before making any material decisions related to any of the products or services described. This article is not intended as, and shall not be construed as, financial advice. The views and opinions expressed in this article are the author’s [company’s] own and do not necessarily reflect those of Vortex.
0 people liked this article