Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Trezor’s Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak Wave

ShipMonk's breach exposed 13,689 customers' data, and it landed in the same fortnight as a separate CEVA Logistics breach that hit Valve, ING and several European retailers.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
August 14, 2026
in Security & Hacks
0 0
Trezor’s Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak Wave

Image by kalhh from Pixabay/Edited by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Trezor disclosed on August 13 that a breach at its shipping partner ShipMonk exposed the personal data of 13,689 customers. It is the third time in just over four years that customer information tied to Trezor has leaked through an outside vendor, not through the wallets or Trezor’s own systems.

ShipMonk told Trezor on August 10 that unauthorized parties had accessed systems holding customer order data. Of those affected, 11,742 people had their full name, email address, phone number and shipping address exposed. Another 1,947 had a narrower set exposed, limited to name, city and email. The customers involved placed orders between May 10 and August 8, a 90-day window that lines up with Trezor’s own data retention policy. Anyone who ordered earlier had their information already deleted from ShipMonk’s systems before the breach happened. The exposure covers seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

 

We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…

— Trezor (@Trezor) August 13, 2026

A second logistics breach in the same two weeks

Trezor’s disclosure did not happen in isolation. In the two weeks before it, CEVA Logistics, a freight and warehousing company with no connection to ShipMonk, was hit by its own intrusion. CEVA’s systems were accessed between July 29 and August 1, and the fallout reached at least eight European warehouses. Valve learned its Steam hardware shipments were affected on August 7 and began notifying customers on August 10, the same day ShipMonk told Trezor about its own breach. ING, the Dutch retailer Bol, the department store De Bijenkorf, the eyewear brand Ace & Tate and the football club Ajax all confirmed their customers’ shipping data was caught up in the CEVA incident.

Nothing ties the two breaches together beyond timing. ShipMonk and CEVA are different companies serving different clients, and neither has said anything connecting the two. What they share is a pattern: two logistics vendors, serving industries as different as cryptocurrency hardware and football merchandise, compromised within roughly the same fortnight, handing attackers the same basic set of information both times: names, home addresses, phone numbers and order details.

A repeat problem for Trezor specifically

For Trezor, ShipMonk is not a new kind of failure. In January 2024, a third-party support ticketing portal was breached, exposing the names, usernames and email addresses of 66,000 people who had contacted Trezor support since December 2021. Attackers used that data in phishing emails asking recipients to hand over their 24-word recovery seed, the information that actually controls a Trezor wallet’s funds.

Before that, in April 2022, Mailchimp, the email platform Trezor used at the time, was breached through social engineering against Mailchimp’s own staff. Attackers used the stolen Trezor mailing list to send a fake data-breach notice urging recipients to download a malicious version of Trezor Suite, again designed to extract seed phrases.

Three incidents, four years, one recurring shape: a vendor handling something Trezor pays out rather than builds itself, email delivery, support ticketing, warehousing and shipping. Trezor said again this week that its own systems were not compromised and that its devices remain secure. Nothing in the ShipMonk breach contradicts that.

What Trezor and ShipMonk haven’t said

Neither Trezor’s blog post nor its social media statement explains how ShipMonk was breached. ShipMonk has said only that it secured the affected systems and is working with Trezor to determine what was accessed. Neither company has named a cause.

A separate, real vulnerability has been circulating in the same news cycle: a critical SQL injection flaw in Metabase, an analytics platform, carried a maximum severity score and let attackers gain administrator access without logging in. Metabase confirmed active exploitation before patching it on August 6. The companies that confirmed being hit by it, on their own blogs and statements, were Framework, Tally, n8n, Kilo Code and ChecklyHQ. ShipMonk was not among them.

The part of this that isn’t about phishing

Trezor is warning customers to expect more phishing by email, phone call and physical mail from people impersonating Trezor, banks or exchanges. That warning matches every previous breach the company has had. What’s different this time is that the leaked data includes a home address attached to a confirmed purchase of a device built to hold cryptocurrency, a more specific piece of information than an email address on a mailing list, and it is now sitting with whoever accessed ShipMonk’s systems. This year’s Bitcoin-related security failures, including the Coldcard firmware flaw that fed into July’s record losses, haven’t stayed confined to any single company’s own hardware; ShipMonk shows the exposure runs through the vendors around that hardware too.

Why this leak specifically raises a physical-safety question

Changpeng Zhao, Binance’s founder, reacted to the breach directly. He wrote on X that the leak “directly links identities and physical addresses to known crypto holders, creating significant phishing, social-engineering and potential physical-security risk.” Chainalysis’s own data shows violent crypto theft, so-called “wrench attacks,” hit $58 million in 2025. In just the first half of 2026, more than $30 million has already been stolen this way. No wrench attack has been tied to the ShipMonk breach. The point isn’t that anyone affected should expect one, it’s that a real name paired with a home address and confirmed proof of owning a hardware wallet is the same starting point these attacks have used elsewhere, which is why the exposure is worth tracking past the usual phishing-alert cycle.

 

Not a great month for hardware wallets.

Trezor disclosed a breach at its shipping provider affecting ~13.7K recent customers. ~11.7K had full name, email, phone and shipping address exposed. Trezor systems/private keys were not compromised. The leak directly links identities and…

— CZ 🔶 BNB (@cz_binance) August 13, 2026

What changes now

Trezor said it is accelerating a feature called Anonymous Delivery, which would let customers collect orders from a locker under a nickname instead of having a hardware wallet shipped to their home under their real name. The company plans to launch that option in the European Union by September and in the United States by the end of the year. Trezor also said it will decide ShipMonk’s future as a partner once it has the full picture of what happened, a decision it can’t make until that picture exists.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: Crypto Hacks
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days
Security & Hacks

More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days

by Saravana Kumar Mahendran
August 31, 2026

More Markets, a lending protocol built on Flow EVM, lost about $9.3 million on Sunday after an attacker used a...

Read moreDetails
Fogo Foundation Says Wallet Breach Sent 400M FOGO Tokens to Unknown Attacker

Fogo Foundation Says Wallet Breach Sent 400M FOGO Tokens to Unknown Attacker

August 29, 2026
Avici Confirms $500,859 Refund to 1,685 Users After Rain Contract Flaw

Avici Confirms $500,859 Refund to 1,685 Users After Rain Contract Flaw

August 29, 2026
Sandbox’s $1 trillion in phantom SAND is still frozen. The real bridge hack cost under $700,000.

Sandbox’s $1 Trillion Phantom SAND Frozen as Real Hack Cost Hits $700K

August 28, 2026
Moonwell Hit by Third Exploit in Nine Months After Attacker Drains Millions in cbBTC

Moonwell Hit by Third Exploit in Nine Months After Attacker Drains Millions in cbBTC

August 27, 2026
Three Cosmos EVM Chains Halt After a Flaw Cosmos Labs Already Called Fixed

Three Cosmos EVM Chains Halt After a Flaw Cosmos Labs Already Called Fixed

August 25, 2026
Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

August 25, 2026
Next Post
Upbit and Bithumb to Delist STORJ, JASMY and TT After Warning Reviews

Upbit and Bithumb to Delist STORJ, JASMY and TT After Warning Reviews

Binance to Halt Transactions With 11 Crypto Platforms Aug. 23

Binance to Halt Transactions With 11 Crypto Platforms Aug. 23

Recommended

  • All
  • Crypto News Today

Verona Launches verUSD Stablecoin With $100 Million in Institutional Commitments

September 29, 2026

Delaware Supreme Court to Review ATG Capital’s Nomination Notice in Empery Digital Board Fight

September 29, 2026

BitMine Immersion Technologies Says Its ETH Holdings Have Topped 6 Million Tokens

September 29, 2026

Bitdeer Expands Bitcoin Mining Deployment to 35 MW at Soluna’s Project Kati 1

September 29, 2026

Strive Adds 1,107 Bitcoin, Bringing Its Treasury to 27,462 BTC

September 29, 2026

DTCC Makes a Strategic Investment in iCapital to Modernize Private Markets Infrastructure

September 29, 2026

Hut 8 Secures a $1.07 Billion Four-Year Revolving Credit Facility Led by JPMorgan

September 29, 2026

Bybit and Franklin Templeton Let Institutions Use Tokenized Fund Shares as Trading Collateral

September 29, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Chainlink Launches CCIP 2.0 With Institutional-Grade Cross-Chain Security Controls
  • Verona Launches verUSD Stablecoin With $100 Million in Institutional Commitments
  • Delaware Supreme Court to Review ATG Capital’s Nomination Notice in Empery Digital Board Fight

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • Uncategorized
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.