At a glance
| Organization | Trezor (via shipping provider ShipMonk) |
| Data exposed | Names, emails, phone numbers, shipping addresses, order numbers |
| People affected | 13,689 initially, plus about 67,000 more (roughly 80,000 total) |
| Cause | Breach of ShipMonk systems; root cause traced to a Metabase flaw |
| Disclosure status | Confirmed by Trezor; investigation ongoing |
| Source | Trezor blog |
TL;DR
A breach at Trezor’s fulfillment partner ShipMonk exposed customer order data. Trezor’s own systems and hardware wallets stayed secure. The main risk to victims is targeted phishing and, for some, physical safety.
What was exposed
The stolen records include full names, phone numbers, email addresses, and shipping addresses. Trezor confirmed the exposure in its official breach notice. In its words, “customer personal information, including full names, phone numbers, email addresses, and shipping addresses, has been accessed by an unauthorized actor during this breach.”
Importantly, no private keys, wallet backups, or devices were touched. Trezor stated plainly, “our systems were not compromised, and your Trezor device is secure.”
How it happened
ShipMonk told Trezor about the intrusion on August 10, 2026. According to breach notices reviewed by BleepingComputer, attackers exploited a flaw in the analytics platform Metabase. That bug was a critical SQL injection zero-day, since patched. So this was a third-party vendor breach, not a hack of Trezor itself.
Who is affected
The first wave hit 13,689 people across seven countries. Of those, 11,742 had full exposure, and 1,947 had partial exposure. Then on September 4, Trezor said the Trezor data breach reached about 67,000 more US customers. Those older orders ran from November 2019 to August 2021.
Trezor blamed ShipMonk for keeping data it had promised to delete. The company said it “repeatedly requested and received written assurance confirming the deletion of the data,” yet the records survived. For now, CoinDesk reports no confirmed misuse of the stolen data.
What affected people should do
Check your inbox for a message from help@trezor.io. No email means you were not affected. Treat any urgent request for personal details with suspicion. Never enter your wallet backup online. Cross-check messages against Trezor’s official channels before acting.
Company response
Trezor apologized and contacted every affected customer directly. It is working with ShipMonk to confirm the full timeline. The firm is also speeding up an Anonymous Delivery option that strips shipping identifiers after delivery. That feature targets the EU by September 2026 and the US by year-end.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!