Full story
ShipMonk breach hits 13,689
Hardware wallet maker Trezor disclosed that an unauthorized party accessed order data held by its shipping provider ShipMonk, exposing personal information tied to 13,689 customers across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
“13,689 customers from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal”
Trezor said the breach affected 11,742 customers whose names, emails, phone numbers and shipping addresses were exposed, and another 1,947 customers whose names, cities and emails were exposed.

In a statement posted on X, Trezor said, "Unfortunately, one of our shipping providers suffered a data breach that exposed sensitive order information."
Trezor also emphasized that its own systems were not compromised and that its devices were secure, while warning affected customers could face targeted phishing attempts using the leaked details.
Phishing risk and what’s safe
Trezor warned that the incident does not compromise wallet devices, private keys, or wallet backups, but it could still increase phishing risk by giving scammers accurate personal data to use in impersonation.
Decrypt reported that Trezor said its own systems were not compromised and that no device, private key or wallet backup was touched, while the company attributed the limited scope to a policy requiring partners to delete or anonymize order data 90 days after delivery.

In its blog-style warning, Trezor told customers, "To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts."
TradingView similarly quoted Trezor saying, "To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts," and added that scammers could use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or impersonate banks, crypto exchanges, or even Trezor.
Broader crypto security stakes
The ShipMonk incident landed as the hardware-wallet ecosystem has faced repeated data-exposure problems through third parties, including Ledger’s January breach tied to its e-commerce partner Global-e and a 2020 incident affecting nearly 300,000 users.
“Chainalysis put the sum stolen at more than $30 million over the same period”
Decrypt said Chainalysis put the sum stolen at more than $30 million in the first half of 2026 and that the year was on course to be the worst on record, while also citing CertiK verification of 52 physical attacks on crypto holders worldwide in the first half of 2026.
CoinDesk reported that extortionists use home addresses to demand ransoms of between $700 and $1,000 and send counterfeit devices by mail directly to victims, framing the indirect risk from leaked logistics records.
Trezor said it was bringing forward an Anonymous Delivery option using locker pickup, neutral packaging, generic sender details and automatic deletion of shipping identifiers, targeting the European Union by September and the United States by the end of the year.



