ShipMonk Breach Exposes 13,689 Trezor Customers

A ShipMonk breach exposed data for about 13,689 Trezor customers, including delivery addresses for 11,742 people. Home invasions targeting crypto owners made up 37% of incidents this year.

A data breach at fulfillment provider ShipMonk exposed personal details for about 13,689 customers who bought Trezor hardware wallets, including delivery addresses for 11,742 orders. ShipMonk notified Trezor on Aug. 10, and Trezor disclosed the incident on Aug. 13.

The fully exposed records cover orders received between May 10 and Aug. 8. An additional 1,947 records containing names, cities and email addresses appear to include older purchases; Trezor said it is working with ShipMonk to determine why those records remained accessible. Trezor said its own systems, devices and services were not breached and that customer wallets and private keys remain secure.

The exposed fields do not include wallet seed phrases or private keys. Company officials and security experts say the leaked names, emails, phone numbers and delivery addresses can increase the effectiveness of phishing and targeted attacks and can be used to identify households likely to hold cryptocurrency.

Industry data show an increase in violent thefts tied to crypto. Chainalysis data place the annual value stolen in violent crypto attacks at $58 million in 2025, with an additional $30 million lost by mid-2026. Home invasions accounted for 37% of recorded incidents this year, up from 26% in 2023. Attackers range from opportunistic thieves who move stolen assets to centralized exchanges to organized groups using laundering infrastructure.

Security leaders urged users and businesses to limit how much personal information links across services. Helius CEO Mert Mumtaz recommended using separate email aliases and unique passwords, switching to hardware-based multi-factor authentication instead of SMS, avoiding unnecessary personal details on orders, and opting for deliveries to shared or non-residential locations where possible. He also encouraged multi-signature wallet setups so a single compromised device does not expose an entire balance.

Trezor said it requires fulfillment partners to delete or anonymize order information within 90 days of delivery to limit lingering data. The company plans an Anonymous Delivery option in the European Union by September 2026 and in the United States by the end of the year. The service will include a dedicated checkout, locker pickup or neutral delivery locations, plain packaging, generic sender details and automatic deletion of shipping identifiers after delivery.

For customers affected by the ShipMonk incident, Trezor recommended treating urgent requests for information with suspicion, verifying messages through official channels, and never sharing a wallet backup or entering it into a website. Trezor and ShipMonk are continuing an investigation to determine which records were exposed and why older records remained accessible.

Articles by this author