Last Update: 09/22/2026 at 11:34 PM EST

ShipMonk Breach Exposes Trezor Customer Data

Coverage from Startup Fortune, COE Security, and others

ShipMonk Breach Exposes Trezor Customer Data topic image

A vulnerability-related intrusion at ShipMonk, a logistics provider used by Trezor, exposed order and contact information for 13,689 customers across seven countries.

The exposed data included names, email addresses, phone numbers, cities and, for many customers, full shipping addresses. Trezor said its systems, hardware wallets, private keys and recovery seeds were not accessed, but the information could enable targeted phishing, impersonation and physical security threats against cryptocurrency holders.

Key Articles4 of 29 articles

If you read one thing

It provides the broadest, clearest account of the breach’s scope, third-party cause, customer risks, and mitigations.

CryptoPotato / Jose Oramas

Best explainer

It explains how a vulnerability in ShipMonk’s third-party analytics environment enabled access to Trezor customer data.

BleepingComputer / Sergiu Gatlan

The evidence

It adds concrete exposure figures and details Trezor’s retention and anonymous-delivery response.

TradingView

Latest development

It captures the Topic’s latest broadening toward AI-assisted phishing and continuing threats to crypto users.

Crypto Briefing
Key Issues

Broad exposure of customer identity and delivery data

The ShipMonk intrusion affected 13,689 Trezor customers across seven countries. Full contact and shipping details were exposed for 11,742 customers, while 1,947 had partial exposure, linking cryptocurrency-wallet purchases to identifiable individuals and, in many cases, home addresses.

Drawn from 5 articles

Third-party data governance is the principal security boundary

The incident places the main security concern at the fulfillment and analytics layer rather than in Trezor’s wallet infrastructure. Reporting attributes access to a vulnerability in ShipMonk’s third-party Metabase environment and highlights vendor access and retention practices as material controls on exposure.

Drawn from 5 articles

Customer targeting risk persists despite secure wallet infrastructure

Exposed names, contact details, and addresses can make phishing, impersonation, fraudulent calls, deceptive mail, and physical targeting more credible for known cryptocurrency users. Trezor says its systems, hardware wallets, and private keys were not compromised, leaving customer targeting—not direct wallet-infrastructure compromise—as the principal immediate risk.

Drawn from 6 articles

Mitigation is shifting toward data minimization and anonymous delivery

Trezor’s 90-day retention policy limited the historical records available to the intruder. The company also plans Anonymous Delivery in the EU and United States during 2026 to reduce the link between wallet purchases, customer identities, and physical addresses.

Drawn from 4 articles

Looking Back
13 Day Timeline
Aug 13Aug 16Aug 20Aug 23Aug 27Aug 30
The Story So Far
Broadening

AI-assisted impersonation broadens the breach’s phishing threat

New reporting adds AI-assisted impersonation as an emerging way attackers could exploit the exposed customer data to target crypto users and seek recovery seeds, while Trezor hardware remains uncompromised.

Previously

A vulnerability-related intrusion at ShipMonk, a logistics provider used by Trezor, exposed order and contact information for 13,689 customers across seven countries. The exposed data included names, email addresses, phone numbers, cities and, for many customers, full shipping addresses. Trezor said its systems, hardware wallets, private keys and recovery seeds were not accessed, but the information could enable targeted phishing, impersonation and physical security threats against cryptocurrency holders.

History
08/24/2026

The account more clearly links the intrusion to a vulnerability and emphasizes third-party access and data-retention risks, while explicitly ruling out compromise of private keys and recovery seeds.

All Articles29 articles
Important24 articles · CI Score 60 and above
Startup Fortune / Walter Schulze
Trezor disclosed on August 13, 2026, that ShipMonk exposed personal data of 13,689 United States hardware-wallet customers, while SafePal's alleged breach remains unconfirmed.
8/17/2026 • Data Breaches & Exposure Events • General
COE Security
Recently, ShipMonk reportedly exposed Trezor customer and order information for nearly 14,000 people across several countries in a third-party breach.
8/14/2026 • Data Breaches & Exposure Events • General
Gridinsoft Blog / Stephanie Adlam
Trezor disclosed on August 13, 2026, that unauthorized access at ShipMonk exposed personal order data belonging to 13,689 customers across seven countries.
8/14/2026 • Data Breaches & Exposure Events • General
Financial Times / Nikou Asgari
Trezor reported that a shipping-provider breach exposed nearly 14,000 customers across seven countries, increasing risks of phishing and physical attacks.
8/13/2026 • Data Breaches & Exposure Events • General
Bitbo
Trezor disclosed on August 10, 2026, that a ShipMonk breach exposed order data for 13,689 customers across seven countries.
8/13/2026 • Data Breaches & Exposure Events • General
TradingView
Trezor disclosed on August 8, 2026, that a shipping-provider breach exposed personal information of 13,689 customers across seven countries.
8/13/2026 • Data Breaches & Exposure Events • General
BeInCrypto / Lockridge Okoth
Trezor said on August 10, 2026, that shipping partner ShipMonk exposed personal data belonging to 13,689 customers across seven countries.
8/13/2026 • Data Breaches & Exposure Events • General
CryptoTicker.io / Rudy Fares
Trezor disclosed on August 13, 2026, that ShipMonk exposed personal order details for 13,689 hardware-wallet customers across seven countries.
8/13/2026 • Data Breaches & Exposure Events • General
CryptoPotato / Jose Oramas
Trezor disclosed in 2026 that a ShipMonk vendor breach exposed order data for 13,689 customers across seven countries, including names, contact details, and some shipping addresses.
8/13/2026 • Data Breaches & Exposure Events • General
Forbes / Boaz Sobrado
Trezor and SafePal disclosed separate vendor-related breaches in August 2026 exposing names, email addresses, and delivery information belonging to 53,487 crypto customers.
8/17/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Sergiu Gatlan
Trezor disclosed in August 2026 that a ShipMonk breach exposed personal data of nearly 14,000 customers in seven countries after attackers exploited Metabase.
8/13/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Sergiu Gatlan
Trezor disclosed on August 10, 2026, that a ShipMonk cyberattack exposed 13,689 customers' order data across seven countries.
8/13/2026 • Data Breaches & Exposure Events • General
CoinStats
In August 2026, ShipMonk exposed contact and shipping information for approximately 14,000 Trezor customers, linking hardware-wallet purchases to identities and residences.
8/15/2026 • Data Breaches & Exposure Events • General
CryptoPotato / Wayne Jones
Trezor disclosed on August 13 that unauthorized access at shipping partner ShipMonk exposed personal information for approximately 13,700 customers.
8/14/2026 • Data Breaches & Exposure Events • General
SC Media
Trezor confirmed that a shipping partner breach exposed personal information from more than 13,000 customers in several countries.
8/14/2026 • Data Breaches & Exposure Events • General
OODA Loop
Trezor disclosed that a shipping-provider breach exposed personal details of nearly 14,000 customers, creating physical and online security risks for cryptocurrency holders.
8/14/2026 • Data Breaches & Exposure Events • General
Yahoo Finance / James Titcomb
Trezor disclosed that a ShipMonk breach exposed 13,689 customers across seven countries, prompting warnings about phishing and physical attacks against cryptocurrency owners.
8/14/2026 • Data Breaches & Exposure Events • General
Claims Journal
Trezor disclosed in 2026 that a shipping-provider breach exposed customer information from recent orders in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
8/14/2026 • Data Breaches & Exposure Events • General
TradingView
Trezor disclosed a shipping-provider breach affecting nearly 14,000 customers across seven countries before August 8, exposing contact and shipping information.
8/13/2026 • Data Breaches & Exposure Events • General
CoinDesk / Olivier Acuna
Trezor reported Thursday that fulfillment partner ShipMonk exposed personal and shipping data for nearly 14,000 customers across seven countries.
8/13/2026 • Data Breaches & Exposure Events • General
Bitcoin Magazine / Mathew Di Salvo
Trezor announced in August that unauthorized access at ShipMonk exposed personal and shipping data from 13,689 customers in seven countries.
8/13/2026 • Data Breaches & Exposure Events • General
Crypto Briefing
Trezor disclosed in 2026 that shipping provider ShipMonk suffered a vendor data breach exposing order information for 13,689 customers across seven countries.
8/13/2026 • Data Breaches & Exposure Events • General
U.Today / Alex Dovbnya
Trezor disclosed that a shipping-provider breach affected nearly 14,000 customers across seven countries, exposing contact and delivery information before August 8.
8/13/2026 • Data Breaches & Exposure Events • General
Bloomberg Law
Trezor disclosed that a shipping-provider breach exposed personal information of thousands of customers in seven countries whose orders were received within 90 days before August 8.
8/13/2026 • Data Breaches & Exposure Events • General
Interesting5 articles · CI Score 45–59
The Merkle / Will Izuchukwu
Coldcard attackers exploited a firmware flaw from July 30, 2026, while Trezor disclosed a shipping-provider breach affecting customers across seven countries.
8/13/2026 • Data Breaches & Exposure Events • General
Renascence
Trezor confirmed that a third-party logistics partner exposed shipping-related details of approximately 13,000 customers, while Trezor systems and crypto assets remained unaffected.
8/25/2026 • Data Breaches & Exposure Events • General
AirdropAlert / Morten Christensen
Trezor customers faced increased phishing risks after a third-party shipping provider leaked personal information from more than 13,000 customers.
8/20/2026 • Data Breaches & Exposure Events • General
Crypto Briefing
Trezor warned cryptocurrency users in August 2026 that a ShipMonk breach and AI-assisted impersonation operation could enable phishing and recovery-seed theft.
8/30/2026 • Cybersecurity (Privacy-Relevant) • General
Cointelegraph / Andrew Fenton
Trezor and SafePal disclosed customer-data breaches in multiple countries, exposing names, addresses, and purchasing information for more than 50,000 hardware-wallet users.
8/16/2026 • Data Breaches & Exposure Events • General