The breach exposed different levels of data for two groups of customers:
The breach was confined to ShipMonk's systems. Trezor's own infrastructure — including its servers, devices, firmware, and the Trezor Suite application — was not compromised . The exposed data was limited to customers in seven countries: the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal
.
The primary risk is targeted phishing and social engineering attacks. Because the leaked data identifies individuals as confirmed Trezor hardware wallet owners and includes their home addresses and phone numbers, attackers can craft highly convincing scams — including physical mail, phone calls, SMS, and emails — pretending to be Trezor support or other trusted entities .
The dataset is considered especially dangerous because it provides a "verified" list of crypto holders at known addresses, making victims more likely to trust fraudulent communications .
If you ordered a Trezor device between May 10 and August 8, 2026, and live in one of the seven affected countries, take these precautions:
Trezor's devices and the crypto funds stored on them remain secure. The risk is entirely to personal information that could be used in social engineering attacks .