Trezor disclosed on August 13 that a breach at its shipping partner ShipMonk exposed the personal data of 13,689 customers. It is the third time in just over four years that customer information tied to Trezor has leaked through an outside vendor, not through the wallets or Trezor’s own systems.
ShipMonk told Trezor on August 10 that unauthorized parties had accessed systems holding customer order data. Of those affected, 11,742 people had their full name, email address, phone number and shipping address exposed. Another 1,947 had a narrower set exposed, limited to name, city and email. The customers involved placed orders between May 10 and August 8, a 90-day window that lines up with Trezor’s own data retention policy. Anyone who ordered earlier had their information already deleted from ShipMonk’s systems before the breach happened. The exposure covers seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…
— Trezor (@Trezor) August 13, 2026
A second logistics breach in the same two weeks
Trezor’s disclosure did not happen in isolation. In the two weeks before it, CEVA Logistics, a freight and warehousing company with no connection to ShipMonk, was hit by its own intrusion. CEVA’s systems were accessed between July 29 and August 1, and the fallout reached at least eight European warehouses. Valve learned its Steam hardware shipments were affected on August 7 and began notifying customers on August 10, the same day ShipMonk told Trezor about its own breach. ING, the Dutch retailer Bol, the department store De Bijenkorf, the eyewear brand Ace & Tate and the football club Ajax all confirmed their customers’ shipping data was caught up in the CEVA incident.
Nothing ties the two breaches together beyond timing. ShipMonk and CEVA are different companies serving different clients, and neither has said anything connecting the two. What they share is a pattern: two logistics vendors, serving industries as different as cryptocurrency hardware and football merchandise, compromised within roughly the same fortnight, handing attackers the same basic set of information both times: names, home addresses, phone numbers and order details.
A repeat problem for Trezor specifically
For Trezor, ShipMonk is not a new kind of failure. In January 2024, a third-party support ticketing portal was breached, exposing the names, usernames and email addresses of 66,000 people who had contacted Trezor support since December 2021. Attackers used that data in phishing emails asking recipients to hand over their 24-word recovery seed, the information that actually controls a Trezor wallet’s funds.
Before that, in April 2022, Mailchimp, the email platform Trezor used at the time, was breached through social engineering against Mailchimp’s own staff. Attackers used the stolen Trezor mailing list to send a fake data-breach notice urging recipients to download a malicious version of Trezor Suite, again designed to extract seed phrases.
Three incidents, four years, one recurring shape: a vendor handling something Trezor pays out rather than builds itself, email delivery, support ticketing, warehousing and shipping. Trezor said again this week that its own systems were not compromised and that its devices remain secure. Nothing in the ShipMonk breach contradicts that.
What Trezor and ShipMonk haven’t said
Neither Trezor’s blog post nor its social media statement explains how ShipMonk was breached. ShipMonk has said only that it secured the affected systems and is working with Trezor to determine what was accessed. Neither company has named a cause.
A separate, real vulnerability has been circulating in the same news cycle: a critical SQL injection flaw in Metabase, an analytics platform, carried a maximum severity score and let attackers gain administrator access without logging in. Metabase confirmed active exploitation before patching it on August 6. The companies that confirmed being hit by it, on their own blogs and statements, were Framework, Tally, n8n, Kilo Code and ChecklyHQ. ShipMonk was not among them.
The part of this that isn’t about phishing
Trezor is warning customers to expect more phishing by email, phone call and physical mail from people impersonating Trezor, banks or exchanges. That warning matches every previous breach the company has had. What’s different this time is that the leaked data includes a home address attached to a confirmed purchase of a device built to hold cryptocurrency, a more specific piece of information than an email address on a mailing list, and it is now sitting with whoever accessed ShipMonk’s systems. This year’s Bitcoin-related security failures, including the Coldcard firmware flaw that fed into July’s record losses, haven’t stayed confined to any single company’s own hardware; ShipMonk shows the exposure runs through the vendors around that hardware too.
Why this leak specifically raises a physical-safety question
Changpeng Zhao, Binance’s founder, reacted to the breach directly. He wrote on X that the leak “directly links identities and physical addresses to known crypto holders, creating significant phishing, social-engineering and potential physical-security risk.” Chainalysis’s own data shows violent crypto theft, so-called “wrench attacks,” hit $58 million in 2025. In just the first half of 2026, more than $30 million has already been stolen this way. No wrench attack has been tied to the ShipMonk breach. The point isn’t that anyone affected should expect one, it’s that a real name paired with a home address and confirmed proof of owning a hardware wallet is the same starting point these attacks have used elsewhere, which is why the exposure is worth tracking past the usual phishing-alert cycle.
Not a great month for hardware wallets.
Trezor disclosed a breach at its shipping provider affecting ~13.7K recent customers. ~11.7K had full name, email, phone and shipping address exposed. Trezor systems/private keys were not compromised. The leak directly links identities and…
— CZ 🔶 BNB (@cz_binance) August 13, 2026
What changes now
Trezor said it is accelerating a feature called Anonymous Delivery, which would let customers collect orders from a locker under a nickname instead of having a hardware wallet shipped to their home under their real name. The company plans to launch that option in the European Union by September and in the United States by the end of the year. Trezor also said it will decide ShipMonk’s future as a partner once it has the full picture of what happened, a decision it can’t make until that picture exists.
AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.
We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.
















