Overview
- Trezor said ShipMonk informed the company of unauthorized access on August 10 and Trezor publicly disclosed the incident on August 13, reporting 13,689 affected customers including 11,742 with names, emails, phone numbers and shipping addresses and 1,947 with partial details.
- Trezor and multiple reports say the company’s own systems and hardware wallets were not breached and that no private keys or wallet backups were accessed.
- The exposed data can be used to craft more convincing phishing emails, phone scams, fraudulent letters and in-person impersonation attempts so Trezor urged affected customers to distrust unsolicited contacts and never enter recovery seeds online.
- ShipMonk says it has secured the affected systems and both companies are investigating how the access occurred, and Trezor says its 90-day partner data retention policy limited the scope of the leak.
- The incident adds to recent vendor and device incidents in the hardware‑wallet space and has led Trezor to notify users, recommend privacy steps such as using pseudonymous emails or P.O. boxes, and to roll out an Anonymous Delivery option in the EU by September with a U.S. launch planned by year‑end.