Trezor states that the order information of 13,689 customers was disclosed because the performance service provider ShipMonk ' s system was not authorized to be accessed. According to the company, Térezor ' s own infrastructure, hardware equipment and wallet backup were not affected, but the incident involved sensitive information such as address and raised concerns about the safety of encrypted users.
Disclosure includes address and telephone
Térezor stated that ShipMonk had informed him on 10 August that it had discovered that the system had been illegally accessed and that the relevant system contained customer order data. The affected users are in countries such as the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
Of these, 11,742 users disclosed information including name, e-mail, telephone number and receiving address. An additional 1,947 users have information on names, cities and e-mails. According to Trezor, part of the latter portion of the records was from an old order 90 days ago and is still being verified.
Increased physical security risks
Such disclosures are sensitive to the fact that receiving information may directly expose the place of residence of the owner of the encrypted asset. The risk is not limited to fishing mail, but may also extend to forged correspondence, telephone fraud and even sub-linear targeting.
Térezor indicated that no cases of fraud or physical assault directly related to the incident had been detected, but that the affected users had been alerted to the need for “immediate processing” of mail, telephone calls or paper-based correspondence and had not been required to enter wallet backups or notes on any website.
Chainalysis had previously indicated that burglary in 2026 had accounted for 37 per cent of the violence associated with encryption, up from 26 per cent in 2023. By mid-year, the amount stolen from violent attacks had been approximately $30 million.
Trezor is about to launch an anonymous distribution.
The incident has also given renewed attention to the privacy of the hardware wallet distribution chain. Térezor stated that preparations were under way to introduce the “anonymous distribution” option to reduce the identifiable information left by purchasing hardware wallets.
It is planned that this distribution will be based on self-deposit, neutral packaging, generic sender information and will automatically remove the distribution identification information upon completion of delivery. Trezor is expected to be online in the EU as early as September 2026 and to expand to the United States market by the end of the year.
Térezor also stated that ShipMonk had taken measures to strengthen the affected systems and that the investigation was continuing. According to the company, the affected customers have been contacted directly through the official security notice and the non-notified customers are outside the scope of the impact.
Additional information:This was the first time since Trezor ' s establishment in 2013 that a client ' s telephone number and receiving address had been exposed as a result of events related to the company itself or its service providers.
