Trezor has told customers that a breach at its shipping fulfilment partner, ShipMonk, exposed personal information belonging to nearly 14,000 buyers of its hardware wallets. The company said its own systems, devices and private keys were unaffected — the exposure is confined to order and shipping records held by the third-party vendor, according to CoinDesk and Protos.
The Block and CoinDesk both reported the toll as “nearly 14,000” customers. Protos put a precise number on it: 13,689. No outlet explains the gap directly. Read narrowly, the discrepancy looks like a rounding difference rather than a substantive disagreement — but that reading is this publication’s inference, not a reconciliation offered by any of the three outlets, and the public reporting simply does not agree on an exact figure.
CoinDesk broke the total into two groups, citing Trezor: 11,742 customers whose names, email addresses, phone numbers and shipping addresses were exposed, and 1,947 customers whose names, cities and email addresses were exposed. Protos described the same split in rounder terms — “nearly 12,000” customers with full contact and address details exposed, and “almost 2,000” with name, city and email exposed.
Trezor announced the breach on X, writing: “We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data.” Both CoinDesk and Protos quoted the post. Trezor said the affected customers span the US, UK, Sweden, Colombia, Brazil, Italy and Portugal, according to CoinDesk and Protos.
Protos alone reported the operational timeline. Trezor told Protos it was informed of the ShipMonk breach on August 10, and that the exposed orders were placed between May 10 and August 8, 2026. Protos also reported that Trezor has not yet decided whether to continue working with ShipMonk, saying the company will “decide on the future” of that partnership once it has a complete picture of the incident.
All three outlets agree on the core facts: ShipMonk was breached, Trezor’s own infrastructure was not, and the exposure creates phishing risk rather than a direct threat to wallets or funds. All three cite the same warning post from Trezor. Where they diverge is precision — The Block and CoinDesk round to nearly 14,000, while Protos gives an exact 13,689. Protos alone carries the order-window and notification dates, and Trezor’s undecided stance on ShipMonk. The Block’s report is the shortest of the three, confirming the top-line figure without a breakdown or timeline.
Trezor told Protos its 90-day policy on deleting or anonymizing order data helped limit the scope of the breach, and said it is pursuing an “anonymous delivery” option this year. The company also stressed, per Protos, that “Nobody from Trezor ever asks for a wallet backup” — a reminder aimed at customers who may now receive phishing attempts referencing real order details.
No outlet has confirmed whether any of the leaked ShipMonk data has been sold, published or used in a scam. Trezor has not announced a final decision on the ShipMonk partnership. And the gap between the rounded “nearly 14,000” figure and Protos’s exact count of 13,689 has not been addressed by any of the three outlets.