The Trezor data breach did not touch your wallet, but a shipping partner exposed around 80,000 customers

The Trezor data breach came through a shipping partner, ShipMonk, not Trezor's own systems, so your wallet and funds are safe. It exposed the personal details of around 80,000 customers, most with a home address and phone number. A phishing wave has already started; here is what leaked and how to stay ahead of the scams.

The Trezor data breach did not touch your wallet, but a shipping partner exposed around 80,000 customers
TL;DR

Hardware-wallet maker Trezor has confirmed a customer-data breach that did not touch its own systems. The exposure came through ShipMonk, an order-fulfilment provider, and the impact widened in early September from an initial 13,689 customers to roughly 80,000 once older order records from a 2019 to 2021 partnership were found to be involved. What leaked is names, email addresses, phone numbers, shipping addresses and order numbers. Devices, private keys and wallet backups are unaffected, so no funds are at direct risk. The real danger is social engineering: affected people are already reporting phishing calls, emails and even physical letters. Trezor will never ask for your wallet backup, so any message that does is a scam. Here is the careful version.

If your Trezor still works and your coins are still there, it is tempting to file this one under "not my problem". Do not. The breach that Trezor confirmed this month is a textbook case of the thing that ought to worry privacy-minded people more than a headline hack: your data leaking from a company you never chose to trust, because the company you did trust handed it to them. Trezor's own systems held. A logistics partner's did not, and the result is that the personal details of around 80,000 hardware-wallet buyers, most of them including phone numbers and home addresses, are now in the wrong hands.

Is my Trezor safe? What leaked, and what did not

The important line first, because it is the one the scammers will try to blur. In Trezor's own words: "To be clear, our systems were not compromised, and your Trezor device is secure." Trezor also stresses that its systems, hardware wallets, private keys and wallet backups were not affected. Nothing in this breach lets anyone move your coins. The exposed data is contact and order information: full names, email addresses, phone numbers, shipping addresses and order numbers. Trezor says the contents of parcels were not exposed.

The scale grew in two steps. Trezor's first disclosure, on 13 August, covered 13,689 customers, with 11,742 fully exposed (name, address, phone, email) and 1,947 partially exposed (name, city, email), all tied to orders placed between 10 May and 8 August 2026. Then, between 2 and 4 September, Trezor was told the same partner still held order data from an earlier engagement running from November 2019 to August 2021, exposing roughly 67,000 more customers with full details. Add the two together and you get about 80,700 people, which is why you will see this reported as roughly 80,000 in some coverage and rounded up to about 81,000 in others. Trezor called it plainly: "This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses."

Why this came from a partner, not from Trezor

The exposure did not come from Trezor's infrastructure at all. It came from ShipMonk, the third party that handled order fulfilment and therefore held the shipping and order records needed to send parcels out. That is the uncomfortable structural lesson here, and it applies far beyond one wallet brand. A company can lock down its own servers, encrypt everything, run a clean security programme, and still watch its customers' data walk out of a vendor's system in its supply chain. The data you give a shop does not stay at the shop; it fans out to logistics, payments and marketing partners, each of which becomes its own point of failure.

Worse, much of the exposed data should not have existed any more. Trezor says the old records were contractually meant to be deleted, and that it had chased this repeatedly: "Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract ..." And yet, as its notice puts it, "despite receiving this confirmation, the data was not deleted in their systems." A deletion promise is only ever as good as the partner's follow-through, and records from 2019 came back to bite customers seven years later. If you care about your data footprint, that is the sentence to remember.

Why a home address is the dangerous part here

For most breaches, a leaked email is an annoyance. For this population, the combination is genuinely hazardous. For most of those on the list, the data pairs a verified name, phone number and home address with proof that the person bought a crypto-hardware wallet, which is a strong signal that they hold cryptocurrency. That is close to a targeting list.

The near-term threat is highly convincing, personalised fraud: a caller or letter that already knows your name, your address and what you bought sounds legitimate in a way a generic spam email never does. The rarer but more serious threat is physical. Help Net Security, citing Chainalysis figures, reported that violent, in-person robberies of crypto holders, a growing pattern of physical attacks on wallet owners, have extracted more than 30 million dollars from victims so far this year. That is a reported industry estimate rather than anything tied to this specific breach, but it is the reason a leaked address matters more for wallet owners than for almost anyone else.

The scams have already started. Here is how to spot them

This is not hypothetical. Affected customers are reporting phishing phone calls, phishing emails and physical letters, some containing QR codes, and Trezor has emailed those affected to warn them. A few rules will defuse almost all of it:

  • Your recovery seed is the only thing that matters, and no one legitimate ever asks for it. In Trezor's words, "Never enter your wallet backup on a website or share it with anyone." The seed is only ever typed into the device itself. Any call, email, letter, website or QR code that asks you to enter, confirm or "verify" your recovery phrase is a scam, full stop.
  • Treat urgency as a red flag. Trezor: "Be suspicious of any communication that prompts immediate action or asks for personal information." Fraud runs on panic and deadlines.
  • Verify through channels you navigate to yourself. Do not click links or scan QR codes from unexpected letters, emails or texts. Type the official address into your browser by hand, and cross-check any claim against Trezor's own blog and verified social channels.
  • Knowing your details is not proof of legitimacy. The whole point of this leak is that a stranger can now recite your name, address and purchase. That is exactly what was stolen, so it authenticates nobody. Do not confirm to a caller that you own a wallet.
  • Watch the edges. Be a little more careful with unsolicited home deliveries and visitors, keep an eye on account statements, and never approve a device action you did not personally start.

What is still unconfirmed

A responsible account has to separate Trezor's confirmed statements from the parts still being pieced together by outside researchers. Several security outlets attribute the intrusion to an extortion group known as ShinyHunters, and report that the entry point was a critical zero-day in a third-party analytics tool used by ShipMonk called Metabase. Both details are sourced to security firms and reporting, not to Trezor, whose own notice does not name a group or a vector, so treat them as reported rather than confirmed. There is also, in the coverage reviewed, no confirmation that the data set has been publicly dumped or sold, so do not assume it has. And the exact headcount is a sum, not a single official figure: 13,689 plus about 67,000, rounded variously to "roughly 80,700" or "about 81,000".

None of that uncertainty changes what you should do. Your wallet is fine. Your address is not private any more. Act accordingly, and be suspicious of anyone who contacts you already knowing too much.

Frequently asked questions

Is my Trezor still safe?

Yes. The breach was at a shipping partner, not Trezor, and it did not touch the device, its firmware, Trezor Suite, your PIN, your private keys or your recovery seed. Your funds are not at direct risk from the breach itself.

What data was leaked in the Trezor breach?

Names, email addresses, phone numbers, shipping addresses and order numbers for affected orders. No recovery seeds, private keys, PINs or wallet backups were involved.

How do I know if I was affected?

Trezor is contacting affected customers directly by email. Confirm your status through Trezor's official website rather than by clicking a link in any message, and treat any unexpected "you were breached" note with suspicion, since scammers are exploiting the news.

Will Trezor ever ask for my recovery phrase?

No, never. Trezor will not ask for your recovery seed, PIN or passphrase by email, phone, text, letter or website. The seed is only ever entered on the Trezor device itself. Anyone who asks for it is a scammer.

How do I spot a Trezor phishing message?

Be wary of urgency, of any demand to "verify" or "authenticate" your wallet, of download prompts, and of QR codes in unexpected letters or emails. Do not click the links or scan those codes. Type the official trezor.io address yourself and check any claim against Trezor's own blog and channels.

What should I do now?

Stay alert to phishing across email, text, phone and post, never enter your seed anywhere except the device, and apply the usual post-breach care with any contact that already knows your name, order or address. You only need to move funds if you actually entered your seed somewhere after a suspicious message.

Should I move my crypto to a new wallet?

Only if you entered your recovery seed into a website, app or form after a suspicious message. If your seed has never left the device, your existing wallet remains secure and moving funds is unnecessary.

Is this the same as the Trezor email phishing?

No. This is the ShipMonk fulfilment breach. A separate email-provider incident and earlier scam-letter campaigns targeting hardware-wallet owners have also been reported; the common thread, and the common defence, is that no legitimate party ever needs your recovery seed.