ShipMonk Breach Exposes Trezor Customer Data
Coverage from Startup Fortune, COE Security, and others

A vulnerability-related intrusion at ShipMonk, a logistics provider used by Trezor, exposed order and contact information for 13,689 customers across seven countries.
The exposed data included names, email addresses, phone numbers, cities and, for many customers, full shipping addresses. Trezor said its systems, hardware wallets, private keys and recovery seeds were not accessed, but the information could enable targeted phishing, impersonation and physical security threats against cryptocurrency holders.
If you read one thing
It provides the broadest, clearest account of the breach’s scope, third-party cause, customer risks, and mitigations.
Best explainer
It explains how a vulnerability in ShipMonk’s third-party analytics environment enabled access to Trezor customer data.
The evidence
It adds concrete exposure figures and details Trezor’s retention and anonymous-delivery response.
Latest development
It captures the Topic’s latest broadening toward AI-assisted phishing and continuing threats to crypto users.
Broad exposure of customer identity and delivery data
The ShipMonk intrusion affected 13,689 Trezor customers across seven countries. Full contact and shipping details were exposed for 11,742 customers, while 1,947 had partial exposure, linking cryptocurrency-wallet purchases to identifiable individuals and, in many cases, home addresses.
Third-party data governance is the principal security boundary
The incident places the main security concern at the fulfillment and analytics layer rather than in Trezor’s wallet infrastructure. Reporting attributes access to a vulnerability in ShipMonk’s third-party Metabase environment and highlights vendor access and retention practices as material controls on exposure.
Customer targeting risk persists despite secure wallet infrastructure
Exposed names, contact details, and addresses can make phishing, impersonation, fraudulent calls, deceptive mail, and physical targeting more credible for known cryptocurrency users. Trezor says its systems, hardware wallets, and private keys were not compromised, leaving customer targeting—not direct wallet-infrastructure compromise—as the principal immediate risk.
Mitigation is shifting toward data minimization and anonymous delivery
Trezor’s 90-day retention policy limited the historical records available to the intruder. The company also plans Anonymous Delivery in the EU and United States during 2026 to reduce the link between wallet purchases, customer identities, and physical addresses.
AI-assisted impersonation broadens the breach’s phishing threat
New reporting adds AI-assisted impersonation as an emerging way attackers could exploit the exposed customer data to target crypto users and seek recovery seeds, while Trezor hardware remains uncompromised.
Previously
A vulnerability-related intrusion at ShipMonk, a logistics provider used by Trezor, exposed order and contact information for 13,689 customers across seven countries. The exposed data included names, email addresses, phone numbers, cities and, for many customers, full shipping addresses. Trezor said its systems, hardware wallets, private keys and recovery seeds were not accessed, but the information could enable targeted phishing, impersonation and physical security threats against cryptocurrency holders.
The account more clearly links the intrusion to a vulnerability and emphasizes third-party access and data-retention risks, while explicitly ruling out compromise of private keys and recovery seeds.
