Protect.Computer
NEWS

Trezor Data Breach Exposes Nearly 14,000 Customers via ShipMonk

· 1 min read · Data hijack Digital scams
Trezor Data Breach Exposes Nearly 14,000 Customers via ShipMonk

Hardware wallet maker Trezor has disclosed a data breach affecting nearly 14,000 of its customers — not because Trezor itself was hacked, but because one of its third-party vendors was. On August 10, 2026, ShipMonk, the shipping and logistics provider Trezor uses to fulfill orders, notified the company that attackers had gained unauthorized access to ShipMonk’s systems. The root cause was a vulnerability in Metabase, a business intelligence tool used by ShipMonk, which the attackers exploited to reach customer order data.

Trezor says 11,742 customers had their information fully exposed — name, email address, phone number, and shipping address — while a further 1,947 had partial exposure, limited to name, city, and email. No Trezor hardware wallets were compromised, no funds are at risk, and Trezor’s own infrastructure was never touched. The concern is secondary: with names, phone numbers, and addresses now in criminal hands, affected customers are prime targets for follow-on phishing campaigns designed to look like communications from Trezor, crypto exchanges, or banks.

How to check if you’re affected

Affected products are any Trezor hardware wallet ordered and shipped via ShipMonk. If your order falls in the breach window, Trezor will notify you directly by email. If you receive any message — email, text, or phone call — claiming your Trezor device is compromised or your seed phrase needs to be “verified,” treat it as a scam. Trezor will never ask for your recovery seed.

Sources

Related reading