Trezor Says ShipMonk Breach Exposed Data of Nearly 14,000 Customers

A ShipMonk breach exposed personal data from nearly 14,000 Trezor customers, increasing the risk of phishing, impersonation, and physical attacks.

Aug 14, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Trezor, the Prague-based manufacturer of cold crypto storage devices, disclosed a significant data breach on Thursday that exposed the personal information of nearly 14,000 customers. 

The incident, which the company described as occurring at its third-party logistics partner ShipMonk, compromised the names, shipping addresses, phone numbers, and email addresses of 11,742 buyers. An additional 1,947 customers had partial data—namely name, city, and email—exposed, with some of those potentially involving older orders that fell outside the standard retention window.

The breach primarily affects customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received devices between May 10 and August 8, 2026. Trezor said the 1,947 partially exposed records may include older orders and that it is still verifying their timeframe.

While Trezor emphasized that its internal systems and the devices themselves remain secure, the company warned that the leak places users at a significantly higher risk of sophisticated phishing campaigns. “We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected,” Trezor said in a statement.

The attack vector

According to breach notifications sent to affected users and reviewed by BleepingComputer, ShipMonk traced the intrusion back to a vulnerability in the third-party analytics platform Metabase. The logistics provider explained that an unauthorized party exploited a critical SQL injection zero-day bug to gain administrative access to their instance. 

Metabase has since patched the vulnerability and invalidated active sessions. Framework and online form builder Tally have also disclosed breaches involving compromised Metabase instances. ShipMonk received extortion emails from ShinyHunters, according to BleepingComputer, although the report did not establish that the group carried out the initial intrusion.

The physical threat

The exposure of physical addresses is particularly alarming given the current climate surrounding digital asset holders. According to blockchain data provider Chainalysis, 46 violent crypto-related incidents were documented worldwide through late June 2026, compared with 40 during the same period in 2025. Kidnappings accounted for 52% of the 2026 incidents.

“Criminals have recognized that crypto holders are high-value targets because they possess wealth in an instantly and irreversibly transferable form,” Chainalysis noted.

Advertisement

This incident marks the first time since Trezor’s founding in 2013 that a breach has exposed customer phone numbers and shipping addresses. It also follows closely on the heels of a separate crisis — the Coldcard hack on July 30 — where over $100 million was stolen due to a bug that generated insecure private keys. 

Ashna Vaghela, chief customer officer at Mercuryo, per Bloomberg, highlighted the overarching concern: “As the Bitcoin industry still absorbs the fallout from the Coldcard hack, the latest incident underlines how quickly trust can be undermined when attackers target the ecosystem around the wallet rather than the wallet itself.”

Moving forward

Trezor is attempting to mitigate this risk with an “Anonymous Delivery” option, which allows buyers to use a dedicated checkout and have devices shipped to neutral lockers in unbranded packaging. The service is slated for a September 2026 launch in the EU and a year-end rollout in the U.S. 

In the meantime, affected users are advised to treat all unsolicited communications with skepticism, verify claims through official Trezor channels, and never enter their 24-word wallet recovery seed online.

Read more: Like the Trezor incident, the DentaQuest breach exposed personal information through a third-party provider, highlighting the security risks organizations inherit from their vendors. 

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.