A security incident at a Trezor shipping provider exposed personal details belonging to 13,689 customers.
The breach affected customers across seven countries, while Trezor confirmed that its wallet systems and devices remain secure.
However, the company warned that exposed details could increase phishing attempts targeting affected users.
Shipping Provider Incident Led to Data Exposure
The incident began after ShipMonk, a shipping provider used by Trezor, suffered unauthorized access to its systems.
As a result, attackers accessed customer information linked to hardware wallet orders processed through the provider.
The exposed information includes names, email addresses, phone numbers, and shipping addresses for some affected customers.
Trezor identified 11,742 customers whose information received full exposure during the incident. Those records included customer names, email addresses, phone numbers, and shipping addresses linked to their orders.
Meanwhile, another 1,947 customers faced partial exposure involving their names, cities, and email addresses.
The affected customers received orders in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal. Trezor said those orders fell within the 90 days before August 8, 2026, when the incident came to light.
Furthermore, the company contacted affected customers through its official email channel and advised them to remain alert.
Trezor Warns Customers About Phishing Threats
Although the breach exposed personal information, Trezor said attackers did not compromise its internal systems.
The company also confirmed that its hardware wallets remain secure and that customer funds remain protected by wallet security.
Therefore, the incident primarily creates a social engineering risk rather than a direct device security threat.
However, leaked contact and shipping information could help criminals create more convincing phishing messages.
Attackers could combine customer names, addresses, and emails to make fraudulent messages appear linked to Trezor orders. Consequently, affected users could face attempts to obtain wallet credentials, recovery phrases, or other sensitive information.
Trezor customers should therefore avoid links from unexpected messages and verify communications through official channels.
Users should also never provide recovery phrases, because legitimate wallet providers do not require those details.
In addition, customers should treat unexpected calls, emails, and messages as potential attempts to steal wallet access.
Trezor Develops Anonymous Delivery Option
The breach has also pushed Trezor to develop a new Anonymous Delivery option for future customers.
The company plans to introduce the service in the European Union by September and in the United States later.
This approach aims to reduce the personal information connected with hardware wallet purchases and deliveries.
The planned option could allow customers to use nicknames or label identification instead of real names.
It could also support automated parcel lockers, which would reduce the need to provide home delivery addresses.
Furthermore, Trezor plans to offer unbranded packaging with generic sender information for additional privacy.
The move highlights the security challenges that crypto companies face beyond their own technology and wallets.
Shipping partners can hold valuable customer information, which makes third-party data protection important for hardware wallet users.
As Trezor responds to the incident, stronger delivery privacy could help reduce similar exposure in future orders.
The incident also follows a separate Coldcard security incident that raised concerns across the crypto self-custody sector.
Galaxy Research estimated that users lost as much as $116 million in Bitcoin during that incident.
Together, the events highlight how personal data and wallet security can create different risks for crypto users.






