S&P 5007,798.99▲0.7% Nasdaq26,803.03▲0.8% Dow53,839.99▲0.1% Russell 2K3,052.85▲0.2% 10-Yr4.64%−4bp VIX14.63+0.08 WTI$81.19▼2.5% Gold$4,408.20▼0.0% EUR/USD1.153▼0.1% BTC$62,608▼1.2% Nikkei67,524▲0.8%
At close · Thu, Aug 13, 2026
Daily Market Updates.

Crypto

HomeCryptoRegulationTrezor says ShipMonk breach exposed thousands of hardw…

Trezor says ShipMonk breach exposed thousands of hardware wallet buyers

The exposure includes delivery addresses for 11,742 orders, increasing the risk of targeted phishing and potential physical targeting of crypto holders.

Trezor disclosed that a breach at its fulfillment provider, ShipMonk, exposed customer data for about 13,689 hardware wallet buyers, including delivery addresses for 11,742 people, after ShipMonk notified the company of an unauthorized systems access on Aug. 10. The company said its own systems, devices, and services were not breached and that customers' wallets remain secure, with no access to private keys or wallet funds.

According to Trezor, the larger set of fully exposed records included names, email addresses, phone numbers, and shipping addresses, covering orders received between May 10 and Aug. 8. An additional 1,947 records included names, cities, and email addresses, which Trezor said may involve older purchases, and it is still working with ShipMonk to determine why those records remained available.

Trezor said fulfillment partners are generally required to delete or anonymize order information within 90 days of delivery, but the breach created a different risk by linking identifiable people, in many cases their home addresses, to the purchase of a hardware wallet. While the exposed data does not grant wallet access, it can make scams more targeted, including phishing and other impersonation via emails, phone calls, and letters.

In its Aug. 13 disclosure, Trezor warned that scammers could tailor messages if they already know a person bought a Trezor device, focusing on alleged wallet security, compromised funds, or account problems rather than generic lures. CryptoSlate also cited past cases where stolen customer databases were used to identify potential hardware wallet owners, including a 2025 Justice Department-described alleged crypto-theft network that used such data and involved residential burglars targeting hardware-wallet victims.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.