Trezor Breach Exposes 14K Users Amid Lazarus Crypto Threats
ShipMonk shipping provider suffered unauthorized access exposing order data for nearly 14,000 Trezor customers Compromised details include full names,

Summary
- ShipMonk shipping provider suffered unauthorized access exposing order data for nearly 14,000 Trezor customers
- Compromised details include full names, shipping addresses, emails and phone numbers
- No funds or keys were compromised, yet the shipmonk data leak spotlights crypto hardware wallet security gaps
Trezor announced the breach on August 12, 2026. ShipMonk suffered unauthorized access that exposed personal order information for 13,689 customers. Someone detected the intrusion around August 10.
The trezor breach fits a pattern of supply-chain attacks on crypto hardware users. It also arrives with fresh reports of Lazarus Group activity.
Context
Hardware wallet makers depend on third-party logistics firms. Those partners store names, addresses, emails, and phone numbers for every buyer. A breach at any one of them spills far beyond the wallet company's own servers.
Trezor keeps a strict 90-day data retention limit with ShipMonk. That rule cut the number of records available during the incident.
Details
The shipmonk data leak revealed full names, shipping addresses, email addresses, and phone numbers for the affected Trezor customers. No seed phrases, private keys, or cryptocurrency holdings were accessed.
Trezor said the short retention window kept exposure limited. The company had already stopped sharing certain fields with the provider in recent months.
"The breach is limited due to Trezor's strict 90-day data storage policy."
, Trezor via @TCryptochicks (X)
The incident aligns with ongoing supply-chain targeting of crypto hardware buyers. It also coincides with continued Lazarus Group operations in cryptocurrency theft. Risks remain for users who hold large amounts in self-custody devices.
Outlook
Trezor customers should watch accounts tied to the exposed emails. They may want extra verification steps for future shipments. The episode shows hardware wallet users still need to check device integrity and follow strong operational security. Core keys stayed safe this time.