Trezor disclosed that its logistics performing partner, ShipMonk, was not authorized to visit, resulting in the disclosure of some of its customers ' names, telephone calls, mailboxes and receiving addresses. The company stated that its own system had not been breached and that the back-up of hardware equipment, private keys and wallets had not been affected.

The leak was concentrated on orders for almost three months.

According to company disclosures, ShipMonk informed Trezor on Monday this week that the system for the storage of customer data was accessed by unauthorized parties. The incident affected a total of 13,689 clients, 11,742 of whom were provided with complete personal information and 1,947 who disclosed their names, cities and mailboxes.

The affected users were mainly placed between 10 May and 8 August and shipped to the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Térezor stated that the clients who had not received the notification were outside the scope of the impact.

Térezor further states that because the cooperating party had to remove or anonymously order data after 90 days of delivery, the earlier order was not retained, which also limited the scope of the leak. According to the company, this was the first time in the past 13 years that a customer ' s telephone number and receiving address had been leaked.

The company warned against fishing and targeted harassment.

Térezor is currently focusing on alerting users to fishing attacks, especially on calls, text messages and mail from strangers. The company stressed that users should not enter wallet backup information on any website.

The risk of such events is not only online. Prior to that, some users had received information on extortion and threats of violence following the large-scale disclosure of customer data in 2020, and others had shown that they had received fishing calls with clear orientation characteristics.

According to CertiK, the chain security company, 52 underline attacks against encryption holders were confirmed globally in the first half of 2026, up from 39 during the same period the previous year. Chainalysis states that losses in related cases exceeded $30 million during the same period.

Anonymized distribution will be online in advance.

Térezor indicated that an anonymous distribution programme was being introduced ahead of time, which included self-referral, neutral packaging, generic sender information and automatic removal of distribution identification information.

According to the company plan, this service will be online in the EU in September and extended to the United States by the end of this year. In recent security incidents in the hardware wallet industry, manufacturers are accelerating the process of adjusting delivery and user privacy protection.

Additional information:Térezor mentioned that users of hardware wallets have also been affected by the Coldcard loophole in the recent past, and that industry concerns about the risk of a linkage between distribution information, identity exposure and asset security are rising.