Trezor Data Breach Exposes Nearly 14,000 Customers via Shipping Partner
A breach at Trezor's fulfillment partner exposed contact and shipping details for nearly 14,000 customers. Here's what's confirmed, what wasn't compromised, and what to watch for.
What Happened
Trezor confirmed nearly 14,000 customers had personal data exposed after ShipMonk, the company's fulfillment partner, suffered unauthorized access to its systems, according to CoinDesk. Of those affected, 11,742 customers had names, email addresses, phone numbers, and shipping addresses exposed. Another 1,947 had names, cities, and email addresses exposed.
Who Is Affected
The breach is limited to customers in seven countries, the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, who placed orders through Trezor's standard fulfillment channel. Per The Block, the exposure covers orders received between May 10 and August 8, 2026. Customers who purchased through Amazon were not affected, since Amazon orders are fulfilled separately.
What Wasn't Compromised
Trezor said its own systems were not affected and that customer wallet devices and funds remain secure. The breach exposed contact and shipping information held by a third-party fulfillment provider, not any data related to private keys, recovery seeds, or wallet access.
Root Cause
According to reporting, the breach originated with Metabase, a data analytics tool used by ShipMonk. An unauthorized party exploited a vulnerability in Metabase's software to access customer order data.
What Trezor Is Warning Customers About
Trezor said it has no confirmed cases of the exposed data being published, sold, or used in a scam so far, but warned that affected customers face a heightened risk of phishing via email, phone, or post. The company noted that scammers could use the leaked contact details to impersonate banks, exchanges, or Trezor itself, and reiterated that Trezor will never ask for a recovery seed phrase under any circumstance.
What to Do If You're Affected
If you ordered a Trezor device between May 10 and August 8, 2026 (outside Amazon), treat unexpected calls, texts, or emails referencing your order as suspicious, even if they include accurate personal details. Never share your 24-word recovery seed with anyone, including someone claiming to be from Trezor support.
If you're evaluating how a platform handles customer data and account security more broadly, you can explore Bitval directly.
This article is for informational purposes only and does not constitute financial or security advice. If you believe you may be affected, refer to Trezor's official communications directly.