LATEST NEWS
SELECTED FOR YOU

14,000 Trezor users put on phishing alert after data breach

ByHannah CollymoreHannah Collymore 2 mins read
14,000 Trezor users put on phishing alert after data breach
  • A breach at ShipMonk, Trezor’s shipping provider, exposed the names and contact details of about 13,689 customers across seven countries. 
  • The people affected face a raised risk of phishing and potential physical targeting. 
  • Trezor says its systems and devices were not compromised, and no misuse of the leaked data has been confirmed yet.

 

Nearly 14,000 Trezor buyers had their names and contact details stolen after ShipMonk, the hardware wallet maker’s shipping partner, was hacked. 

The people affected now face a heightened risk of phishing and, in some cases, theft at their home addresses, as French users have experienced.

What details were exposed in the Trezor leak? 

Trezor reported via its blog post that it became aware of the breach of the systems holding its order data when ShipMonk shared the information on Monday, August 10. 

Specifically, the orders shipped between May 10 and August 8 were affected, Trezor’s own infrastructure was untouched, and user wallets themselves remain secure. 

The company said there are 11,742 people whose names, email addresses, phone numbers, and shipping addresses were all taken, and another 1,947 who only had their names, cities, and email addresses taken. That puts the running total at 13,689 victims. 

Trezor revealed that the buyers spanned seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. 

The damage was slightly minimized due to ShipMonk’s policy of deleting or anonymizing order records three months after delivery. Trezor said that customers who bought through Amazon were spared as those orders moved through a different fulfillment channel.

The company has experienced similar incidents in the past, but Trezor said this was the first attack to expose customer phone numbers and shipping addresses. The company’s third-party support portal was breached in January 2024, affecting  66,000 users, and a separate 2022 event affected more than 106,000.  

How did the Trezor hack happen? 

ShipMonk said the attackers took advantage of a flaw in Metabase, an analytics platform it uses. Metabase publicly flagged the problem itself on August 6. 

The bug was a critical SQL injection zero-day that handed intruders administrator access, and the same campaign hit other companies, including laptop maker Framework and form builder Tally. 

Since then, despite Trezor saying it has no evidence the stolen records have been published, sold or used in any scam so far, ShipMonk has been receiving extortionary emails from the ShinyHunters group.

Ledger, Trezor’s main rival, saw a 2020 breach spill data on hundreds of thousands of users, and, as Cryptopolitan has reported, scammers were still mailing Ledger owners fake “Quantum Resistance Security Update” letters with malicious QR codes as recently as May 2026. Ledger disclosed a separate leak through its payment processor Global-e in January.

Worryingly, criminals have started using leaked personal data to pick targets for kidnappings and home invasions aimed at forcing victims to surrender their crypto. Chainalysis reported that more than $30 million was taken in violent attacks in the first half of 2026, and it is on track to pass 2025’s full-year figure of $58 million. 

Trezor said affected customers were notified by email. It is also promising a more private shipping option equipped with lockers, neutral packaging, and automatic deletion of address data after delivery, aiming to launch in the EU by September and in the U.S. by year’s end.

The smartest crypto minds already read our newsletter. Want in? Join them.

FAQs

How many Trezor customers were affected and what data was taken?

About 13,689 customers were affected: 11,742 had their names, emails, phone numbers and shipping addresses exposed, and another 1,947 had only their names, cities and emails leaked.

How did the ShipMonk breach happen?

ShipMonk told customers that attackers exploited a critical vulnerability in Metabase, a third-party analytics platform, gaining access to order data before the flaw was patched.

Are Trezor devices or funds at risk from this breach?

No. Trezor said its own systems were not compromised and the wallets remain secure; the main risk is that affected customers may face more phishing attempts by email, phone or post.

Share this article

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore

Hannah Collymore

Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.

MORE … NEWS