Back to News
Trezor shipping provider breach exposes personal data of nearly 14,000 customers
By Exbasi Intelligence
Sourced from The Block
Nearly 14,000 Trezor customers had their personal information exposed in a breach at shipping provider ShipMonk, most of whom had their names, phone numbers and home addresses exposed.According to a Trezor announcement late Wednesday, ShipMonk informed the hardware wallet manufacturer on Monday that an unauthorized party had accessed the systems holding customer order data.It specified that the names, email addresses, phone numbers and shipping addresses of 11,742 customers had been exposed. Another 1,947 customers had their names, cities and email addresses leaked, bringing the rough estimate of victims to around 13,700 across the U.S., UK, Sweden, Colombia, Brazil, Italy and Portugal.Trezor said the breach does not affect its internal systems and that the hardware wallets themselves remain secure."This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses," the company said.The exposed customers are now at a higher risk of being targeted by phishing campaigns, where attackers may reach out impersonating Trezor, banks or crypto exchanges and use the information in an attempt to trick the users out of more sensitive information or their assets.Similar incidents have also occurred to rival wallet maker Ledger. In January, Ledger customers were alerted that names and contact information had been exposed following unauthorized access to order data held by third-party e-commerce provider Global-e.In 2020, a larger Ledger breach exposed information belonging to more than 270,000 customers after attackers accessed marketing and e-commerce data. Names, email addresses, phone numbers and, in some cases, home addresses were later published on a hacking forum, leading to phishing attempts and reports of harassment.Even six years later, customers still report receiving phone calls and even physical letters from fraudsters impersonating Ledger, trying to trick the customers into giving up their seed phrases or other sensitive information.But phishing and proxy attempts are the lesser of two evils in cases like this where home addresses are involved. Criminals have become more brazen in using personal information to identify targets for kidnappings, home invasions and other physical attacks intended to force victims to hand over their crypto.On Wednesday, it was reported that a French couple was targeted in three home invasions in less than a month this summer after moving into a house formerly owned by crypto millionaires whose tax information and address had leaked onto the dark web, according to local reporting.Recent data from Chainalysis found that more than $30 million had been stolen in violent attacks in the first half of 2026, putting it on pace to surpass 2025's full-year total of $58 million.Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.