Skip to main content
LiMP VPN
All news

Trezor Warns of Phishing After ShipMonk Supply Chain Breach

Trezor Warns of Phishing After ShipMonk Supply Chain Breach

In short: On August 10, 2026, Trezor's shipping fulfillment partner ShipMonk disclosed unauthorized access to its systems via a vulnerability in the third-party analytics platform Metabase. Personal data belonging to 13,689 Trezor customers — names, email addresses, phone numbers, and home delivery addresses — was exposed. Hardware wallets, private keys, and cryptocurrency assets were not affected, but targeted phishing risk is now significantly elevated for those affected.

What Happened

On August 14, 2026, Trezor published an official incident notification. Between May 10 and August 8, 2026, order data from customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal was processed and stored by ShipMonk as part of a standard fulfillment arrangement. On August 10, ShipMonk notified Trezor that an attacker had gained unauthorized access to those records by exploiting a vulnerability in Metabase, a business intelligence tool used to process order data.

Trezor was clear that the breach occurred within ShipMonk's infrastructure, not on Trezor's own servers. Yet customer personal data was compromised precisely because it was being held by an external partner — a textbook supply chain attack, where attackers bypass a hardened primary vendor and exploit a weaker link in its supplier ecosystem. For context on how attackers weaponize this kind of data, see our article on remote access and social engineering scams.

All 13,689 affected customers were individually notified by Trezor via email from help@trezor.io. The company also announced it is accelerating the rollout of an Anonymous Delivery option: orders will route through parcel lockers in neutral packaging without brand identification, and shipping data will be automatically deleted after delivery.

What Data Was Exposed

According to Trezor's official disclosure, the incident affected:

  • 11,742 customers whose full names, email addresses, phone numbers, and home delivery addresses were exposed;
  • 1,947 additional customers whose partial data was exposed: names, email addresses, and city information.

What was not affected: the hardware wallets themselves, private keys, seed phrases (recovery mnemonics), and cryptocurrency assets. Trezor account credentials were also not compromised. If you own a Trezor device and your seed phrase has never been shared with anyone or entered on a third-party website, your cryptocurrency remains secure.

Why This Breach Carries Higher Risk Than a Typical Data Leak

The combination of a real name, email address, phone number, home address, and the confirmed fact of hardware wallet ownership creates an unusually high-value targeting profile. Here is how that data gets weaponized:

  • Convincing phishing emails. An attacker who knows your name and that you own a Trezor device can craft highly credible messages impersonating Trezor support, asking you to verify your device or apply a critical firmware update via a fake site designed to steal your seed phrase.
  • Physical mail attacks. Trezor explicitly warned that fraudulent physical letters may be sent to exposed home addresses. A convincing-looking package with fraudulent instructions is an emerging attack vector against hardware wallet holders.
  • Smishing and vishing. Exposed phone numbers enable SMS-based attacks and impersonation calls, including AI voice synthesis impersonating customer support agents.
  • Cross-breach correlation. Criminals routinely merge datasets from multiple incidents. Trezor shipping data combined with exchange credentials or email service breaches from other leaks creates far richer targeting profiles.

The free service HaveIBeenPwned lets you check whether your email address has appeared in known data breaches — enable alerts to be notified automatically when new incidents are indexed.

The Supply Chain Problem: A Structural Vulnerability

This incident illustrates a structural challenge: even a company with strong direct security controls cannot fully guarantee the security posture of every third-party vendor in its supply chain. Trezor has a well-earned reputation for protecting cryptocurrency assets, but shipping data was held by an external fulfillment partner whose analytics tooling turned out to be the weakest link in the chain.

When evaluating any online service, it is worth asking not just about the provider's own security practices, but about what third-party tools and partners it shares your data with. For a broader guide on reducing your digital footprint, visit our privacy and security blog.

LiMP VPN encrypts your traffic and hides your IP address at the network level, protecting data in transit from interception. It does not prevent a server-side breach at a third-party vendor where your data is already stored. These are complementary, independent protection layers. See the LiMP VPN features page for a clear breakdown of what network-level protection covers — and what it does not.

Steps to Take if You Are an Affected Trezor Customer

  1. Never enter your seed phrase online. The only safe place for a seed phrase is a physical offline record. Any request for your seed phrase via email, phone, physical mail, or website is a scam, without exception.
  2. Ignore urgent communications supposedly from Trezor. Legitimate companies do not demand immediate device verification or fund transfers through any channel.
  3. Access trezor.io only by typing the address manually. Do not follow links from emails or messages — open your browser and navigate to the site directly.
  4. Enable two-factor authentication on all accounts linked to cryptocurrency: exchanges, email services, and wallet management platforms.
  5. Subscribe to HaveIBeenPwned alerts. You will be automatically notified when your email address appears in newly indexed breach datasets.

Sources

Trezor Warns of Phishing After ShipMonk Supply Chain Breach