Trezor confirmed late Wednesday that an intrusion at ShipMonk, one of its fulfilment providers, exposed personal data belonging to 13,689 buyers. For 11,742 of them, the leak covers name, email, phone number and shipping address. Wallets, firmware and the manufacturer’s own infrastructure were untouched. What did move is a list naming people who physically hold a hardware wallet.
Key Takeaways
- An intrusion at logistics provider ShipMonk exposed data on 13,689 Trezor customers.
- 11,742 full records include the shipping address and the phone number.
- Violent attacks on crypto holders climbed to roughly 4.6 per month in the first half.
A SQL Injection at the Shipper, Not the Manufacturer
The origin sits outside Trezor’s walls. ShipMonk reported unauthorized access on Monday to systems holding customer order records, exploited through a Metabase zero-day SQL injection. The same flaw was used against Framework and Tally.
The manufacturer disclosed the incident on Wednesday evening in a security note posted to its official blog. The count is precise: 11,742 customers had their name, email, phone number and shipping address exposed, while 1,947 others lost only their name, city and email.
The window covers orders delivered between May 10 and August 8, shipped to the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Affected buyers received a message from [email protected]. Anyone who got nothing is outside the exposed set.
One governance detail contained the damage. Trezor requires its providers to purge shipping identifiers after 90 days, which put every order placed before May 10 out of reach.
Trezor noted this is the first time since its 2013 founding that a breach exposed customer phone numbers and shipping addresses. The lesson moves toward a link almost no buyer audits: whoever loads the parcel onto the truck. The previous alarm hit the hardware itself, in the Coldcard flaw that drained $70M in forty-one minutes.
What a Hardware Wallet Owner’s Address Is Worth
A file linking an identity, a home address and a hardware wallet purchase is not an ordinary customer list. It names people who probably hold crypto in self-custody, with no intermediary able to freeze a transfer. We walked through that control-versus-exposure tradeoff in our comparison of cold and hot wallet setups.
The first risk is tailored phishing. A message quoting the right name, the right city and the right order date clears mental defenses that a generic email never gets past. Impersonation will target the brand, but banks and exchanges too. We documented that vector when an onchain investigator picked the sector apart in our piece on hardware wallets under ZachXBT’s scrutiny.
The second risk is not digital at all. Chainalysis data on violent attacks targeting crypto holders shows a clear acceleration: roughly 4.6 attacks per month in the first half, against 1.9 per month across all of 2025. Stolen value nears $30M at midyear, after a record $58M in 2025.
The mix matters as much as the volume. Home invasions account for 37% of 2026 incidents against 26% in 2023, and kidnappings hold steady near 52% of the total. Global incident counts reached 46 through late June, against 40 at the same point last year.
Geography sharpens the point further. France, the United States, Brazil and Thailand carry the heaviest cumulative counts since 2023, and France in particular has run far above its own historical baseline this year. Three of those four markets appear in the list of destinations covered by the ShipMonk window.
The Ledger precedent sets the time horizon. Its 2020 leak exposed more than 270,000 customers, and some victims still field fraudulent approaches six years on. A stolen address cannot be revoked, unlike a password.
Also on Cryptonomic:
- SEC Pulls Its Reg Crypto Meeting With No New Date
- Bitwise Cuts 14% of Staff After a 31% Asset Drop
- Solana Nearly Stopped After a Hosting Provider Outage
Anonymous Delivery Lands After the Threat
Trezor is answering with an anonymous delivery option: a dedicated checkout, locker pickup, neutral packaging, generic sender details and automatic deletion of shipping identifiers once the parcel is handed over.
The timeline targets the European Union in September and the United States before year end. The move points the right way, though it arrives after the very incident it would have prevented, and it does nothing for the 13,689 records already out.
For a buyer, the practical response comes down to one reflex. Treat every inbound contact referencing a hardware order as hostile, however accurate its details look, because accuracy is precisely what the leak bought the attacker.
The episode traces a structural shift. Attackers now route around cryptographic setups that have become genuinely hard, and aim at the peripheral layers instead: the shipper, the internal reporting tool, the payment provider. That same logic hit Bitcoin payments in early August through the BTCPay Server flaw that drained Lightning nodes.
Not a single bitcoin moved in this affair, and that nuance is what makes the damage hard to price. What leaked is the set of coordinates telling an attacker where to strike next. The value of that file will not be measured this week.
Follow the story on Cryptonomic.


