Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Trezor’s Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak Wave

ShipMonk's breach exposed 13,689 customers' data, and it landed in the same fortnight as a separate CEVA Logistics breach that hit Valve, ING and several European retailers.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
August 14, 2026
in Security & Hacks
0 0
Trezor’s Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak Wave

Image by kalhh from Pixabay/Edited by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Trezor disclosed on August 13 that a breach at its shipping partner ShipMonk exposed the personal data of 13,689 customers. It is the third time in just over four years that customer information tied to Trezor has leaked through an outside vendor, not through the wallets or Trezor’s own systems.

ShipMonk told Trezor on August 10 that unauthorized parties had accessed systems holding customer order data. Of those affected, 11,742 people had their full name, email address, phone number and shipping address exposed. Another 1,947 had a narrower set exposed, limited to name, city and email. The customers involved placed orders between May 10 and August 8, a 90-day window that lines up with Trezor’s own data retention policy. Anyone who ordered earlier had their information already deleted from ShipMonk’s systems before the breach happened. The exposure covers seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

 

We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…

— Trezor (@Trezor) August 13, 2026

A second logistics breach in the same two weeks

Trezor’s disclosure did not happen in isolation. In the two weeks before it, CEVA Logistics, a freight and warehousing company with no connection to ShipMonk, was hit by its own intrusion. CEVA’s systems were accessed between July 29 and August 1, and the fallout reached at least eight European warehouses. Valve learned its Steam hardware shipments were affected on August 7 and began notifying customers on August 10, the same day ShipMonk told Trezor about its own breach. ING, the Dutch retailer Bol, the department store De Bijenkorf, the eyewear brand Ace & Tate and the football club Ajax all confirmed their customers’ shipping data was caught up in the CEVA incident.

Nothing ties the two breaches together beyond timing. ShipMonk and CEVA are different companies serving different clients, and neither has said anything connecting the two. What they share is a pattern: two logistics vendors, serving industries as different as cryptocurrency hardware and football merchandise, compromised within roughly the same fortnight, handing attackers the same basic set of information both times: names, home addresses, phone numbers and order details.

A repeat problem for Trezor specifically

For Trezor, ShipMonk is not a new kind of failure. In January 2024, a third-party support ticketing portal was breached, exposing the names, usernames and email addresses of 66,000 people who had contacted Trezor support since December 2021. Attackers used that data in phishing emails asking recipients to hand over their 24-word recovery seed, the information that actually controls a Trezor wallet’s funds.

Before that, in April 2022, Mailchimp, the email platform Trezor used at the time, was breached through social engineering against Mailchimp’s own staff. Attackers used the stolen Trezor mailing list to send a fake data-breach notice urging recipients to download a malicious version of Trezor Suite, again designed to extract seed phrases.

Three incidents, four years, one recurring shape: a vendor handling something Trezor pays out rather than builds itself, email delivery, support ticketing, warehousing and shipping. Trezor said again this week that its own systems were not compromised and that its devices remain secure. Nothing in the ShipMonk breach contradicts that.

What Trezor and ShipMonk haven’t said

Neither Trezor’s blog post nor its social media statement explains how ShipMonk was breached. ShipMonk has said only that it secured the affected systems and is working with Trezor to determine what was accessed. Neither company has named a cause.

A separate, real vulnerability has been circulating in the same news cycle: a critical SQL injection flaw in Metabase, an analytics platform, carried a maximum severity score and let attackers gain administrator access without logging in. Metabase confirmed active exploitation before patching it on August 6. The companies that confirmed being hit by it, on their own blogs and statements, were Framework, Tally, n8n, Kilo Code and ChecklyHQ. ShipMonk was not among them.

The part of this that isn’t about phishing

Trezor is warning customers to expect more phishing by email, phone call and physical mail from people impersonating Trezor, banks or exchanges. That warning matches every previous breach the company has had. What’s different this time is that the leaked data includes a home address attached to a confirmed purchase of a device built to hold cryptocurrency, a more specific piece of information than an email address on a mailing list, and it is now sitting with whoever accessed ShipMonk’s systems. This year’s Bitcoin-related security failures, including the Coldcard firmware flaw that fed into July’s record losses, haven’t stayed confined to any single company’s own hardware; ShipMonk shows the exposure runs through the vendors around that hardware too.

Why this leak specifically raises a physical-safety question

Changpeng Zhao, Binance’s founder, reacted to the breach directly. He wrote on X that the leak “directly links identities and physical addresses to known crypto holders, creating significant phishing, social-engineering and potential physical-security risk.” Chainalysis’s own data shows violent crypto theft, so-called “wrench attacks,” hit $58 million in 2025. In just the first half of 2026, more than $30 million has already been stolen this way. No wrench attack has been tied to the ShipMonk breach. The point isn’t that anyone affected should expect one, it’s that a real name paired with a home address and confirmed proof of owning a hardware wallet is the same starting point these attacks have used elsewhere, which is why the exposure is worth tracking past the usual phishing-alert cycle.

 

Not a great month for hardware wallets.

Trezor disclosed a breach at its shipping provider affecting ~13.7K recent customers. ~11.7K had full name, email, phone and shipping address exposed. Trezor systems/private keys were not compromised. The leak directly links identities and…

— CZ 🔶 BNB (@cz_binance) August 13, 2026

What changes now

Trezor said it is accelerating a feature called Anonymous Delivery, which would let customers collect orders from a locker under a nickname instead of having a hardware wallet shipped to their home under their real name. The company plans to launch that option in the European Union by September and in the United States by the end of the year. Trezor also said it will decide ShipMonk’s future as a partner once it has the full picture of what happened, a decision it can’t make until that picture exists.

AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.

We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.

Disclaimer: Cryip’s content is strictly for informational purposes and does not constitute financial, legal, or investment advice. Asset references are not endorsements, and readers assume full responsibility for any financial decisions.
Tags: Crypto Hacks
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Boltz Hands Over Control, But Won’t Say Who’s Taking It or How Much Was Lost
Market Updates

Boltz Hands Over Control, But Won’t Say Who’s Taking It or How Much Was Lost

by Saravana Kumar Mahendran
August 13, 2026

Boltz's three founders stepped down from the company on Aug. 13, handing control of the non-custodial Bitcoin swap service to...

Read moreDetails
Harmony Confirms Suspected Exploit as ONE Price Drops Over 30%

Harmony Confirms Suspected Exploit as ONE Price Drops Over 30%

August 12, 2026
Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

August 8, 2026
Coldcard Hack Losses Nearly $100 Million

Coldcard Hack Losses Nearly $100 Million as Root Cause Reveals a Wider Flaw

August 4, 2026
Boltz Disables Bitcoin Swaps Indefinitely After Monthslong AI-Assisted Attacks

Boltz Disables Bitcoin Swaps Indefinitely After Months long AI-Assisted Attacks

August 4, 2026
BitGo’s Belshe Dares Anthropic to Hack His Bitcoin Wallet, Again

BitGo’s Belshe Dares Anthropic to Hack His Bitcoin Wallet, Again

August 3, 2026
July 2026 Crypto Hacks: Nearly $200M Lost Across Wallets, DeFi and Bridges

July 2026 Crypto Hacks: Nearly $200M Lost Across Wallets, DeFi and Bridges

August 1, 2026

Recommended

  • All
  • Crypto News Today
JPMorgan Closed Polymarket Account While Pursuing Its IPO

JPMorgan Closed Polymarket Account While Pursuing Its IPO

August 14, 2026
Baltimore’s Kalshi Case Rests on a Warning Letter With Casino-Lobby Roots

Baltimore’s Kalshi Case Rests on a Warning Letter With Casino-Lobby Roots

August 14, 2026
Tether Completes First Big Four Audit, Reporting $6.8B Reserve Surplus

Tether Completes First Big Four Audit, Reporting $6.8B Reserve Surplus

August 14, 2026
MSCI Proposal Puts Strategy and Metaplanet at Risk of Index Removal

MSCI Proposal Puts Strategy and Metaplanet at Risk of Index Removal

August 14, 2026
BitGo Q2 2026: Revenue Jumps 80% as Margins Narrow

BitGo Q2 2026: Revenue Jumps 80% as Margins Narrow

August 13, 2026
Mirae Asset Injects ₩50 Billion Into Digital X Weeks After Renaming Korbit

Mirae Asset Injects ₩50 Billion Into Digital X Weeks After Renaming Korbit

August 13, 2026
Solana Network Stays Online Despite Validator Infrastructure Failure

Solana Network Stays Online Despite Validator Infrastructure Failure

August 13, 2026
Charles Schwab Expands Retail Crypto Access With Direct Bitcoin and Ether Trading

Charles Schwab Expands Retail Crypto Access With Direct Bitcoin and Ether Trading

August 13, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Trezor’s Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak Wave
  • JPMorgan Closed Polymarket Account While Pursuing Its IPO
  • Baltimore’s Kalshi Case Rests on a Warning Letter With Casino-Lobby Roots

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.