Trezor, the Prague-based manufacturer of cold crypto storage devices, disclosed a significant data breach on Thursday that exposed the personal information of nearly 14,000 customers.
The incident, which the company described as occurring at its third-party logistics partner ShipMonk, compromised the names, shipping addresses, phone numbers, and email addresses of 11,742 buyers. An additional 1,947 customers had partial data—namely name, city, and email—exposed, with some of those potentially involving older orders that fell outside the standard retention window.
The breach primarily affects customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received devices between May 10 and August 8, 2026. Trezor said the 1,947 partially exposed records may include older orders and that it is still verifying their timeframe.
While Trezor emphasized that its internal systems and the devices themselves remain secure, the company warned that the leak places users at a significantly higher risk of sophisticated phishing campaigns. “We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected,” Trezor said in a statement.
The attack vector
According to breach notifications sent to affected users and reviewed by BleepingComputer, ShipMonk traced the intrusion back to a vulnerability in the third-party analytics platform Metabase. The logistics provider explained that an unauthorized party exploited a critical SQL injection zero-day bug to gain administrative access to their instance.
Metabase has since patched the vulnerability and invalidated active sessions. Framework and online form builder Tally have also disclosed breaches involving compromised Metabase instances. ShipMonk received extortion emails from ShinyHunters, according to BleepingComputer, although the report did not establish that the group carried out the initial intrusion.
The physical threat
The exposure of physical addresses is particularly alarming given the current climate surrounding digital asset holders. According to blockchain data provider Chainalysis, 46 violent crypto-related incidents were documented worldwide through late June 2026, compared with 40 during the same period in 2025. Kidnappings accounted for 52% of the 2026 incidents.
“Criminals have recognized that crypto holders are high-value targets because they possess wealth in an instantly and irreversibly transferable form,” Chainalysis noted.
This incident marks the first time since Trezor’s founding in 2013 that a breach has exposed customer phone numbers and shipping addresses. It also follows closely on the heels of a separate crisis — the Coldcard hack on July 30 — where over $100 million was stolen due to a bug that generated insecure private keys.
Ashna Vaghela, chief customer officer at Mercuryo, per Bloomberg, highlighted the overarching concern: “As the Bitcoin industry still absorbs the fallout from the Coldcard hack, the latest incident underlines how quickly trust can be undermined when attackers target the ecosystem around the wallet rather than the wallet itself.”
Moving forward
Trezor is attempting to mitigate this risk with an “Anonymous Delivery” option, which allows buyers to use a dedicated checkout and have devices shipped to neutral lockers in unbranded packaging. The service is slated for a September 2026 launch in the EU and a year-end rollout in the U.S.
In the meantime, affected users are advised to treat all unsolicited communications with skepticism, verify claims through official Trezor channels, and never enter their 24-word wallet recovery seed online.
Read more: Like the Trezor incident, the DentaQuest breach exposed personal information through a third-party provider, highlighting the security risks organizations inherit from their vendors.





