The company confirmed a data breach on August 13, 2026, and this is the latest Trezor data breach news from the hardware wallet industry .
The incident came from ShipMonk, a third-party shipping and logistics provider that handles firm's order fulfillment. ShipMonk told company on Monday, August 10, 2026, that an unauthorized party had accessed its systems. The company devices and wallet backups were not affected.
The incident hit new customers who placed orders in the 90 days before August 8, 2026. Affected regions include the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The company said its own infrastructure remained secure throughout the incident.

Source: Official Website
According to company's official blog, ShipMonk stores basic delivery information needed to ship a package. This includes names, email addresses, phone numbers, and shipping addresses.
| Exposure Type | Information Exposed | Customers Affected |
| Full exposure | Name, email, phone number, shipping address | 11,742 |
| Partial exposure | Name, city, email | 1,947 |
The firm's 90-day records retention policy limited the damage. Order details older than 90 days had already been deleted from ShipMonk's systems under the same policy applied to fulfillment partners.
This Trezor data breach news matters because exposed shipping records raises phishing risk. Attackers can use real names, addresses, and phone numbers to send convincing scam messages.
The company repeated its core security advice:
Never enter a wallet backup (seed phrase) on any website
Only trust updates from official channels
Treat unexpected messages about the incident with suspicion
The company published its public disclosure on August 13, 2026, through its official blog and X account. All affected customers received a separate notification email.
ShipMonk told customers the exposure traced back to a vulnerability in Metabase, a third-party analytics tool that has since been patched. According to update, this marks the first incident in the company's 13-year history to expose customer phone numbers and shipping addresses.
This Trezor data breach news adds to a growing list of third-party vendor hacks across the crypto hardware sector.
The company said it is working with ShipMonk to confirm the full scope of the incident and is investigating what information was accessed. The company added that further updates on the investigation will be posted through its official blog.
For now, this Trezor data breach news centers on shipping details, not wallet security. Company is moving up its anonymous delivery option, aiming for an EU launch by September 2026 and a US launch by the end of 2026. The company called this project a top priority.
The new checkout flow is built to remove the direct link between a hardware wallet purchase and a customer's real identity or home address. Trezor outlined the following features:
A dedicated checkout separate from the standard order flow
A nickname or label ID instead of a real name
An automated parcel locker for pickup, instead of home delivery
Unbranded packaging with a generic sender label
A pickup PIN sent by email or SMS, so no name or address travels with the package

Source: Official X Post
The firm has not shared full technical details on how the checkout or locker system will work. The company also did not state whether this rollout is a direct response to the ShipMonk incident or a plan that was already underway.
The bigger takeaway from this Trezor data breach news is that supply chain vendors carry real risk, even when a company's core systems stay secure. The exposed details does not include private keys or wallet backups, which limits direct financial loss.
Phishing risk still rises whenever real names and addresses circulate outside a company's own systems. Trezor's shift toward locker-based, identity-light delivery reflects a broader industry move to reduce the link between crypto purchases and real-world identity.
This Trezor data breach news confirms that customer shipping information, not wallet security, was at the center of the incident. Trezor devices, firmware, and backups remain unaffected. Affected customers should stay alert for phishing attempts and rely only on official channels for updates.
YMYL Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always verify security incidents through official company channels.