{"investigation":{"slug":"trezor-shipmonk-data-breach","entity_name":"Trezor (ShipMonk Data Breach)","trust_score":58,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"published","content_type":"investigation","summary":"On August 10, 2026, Trezor disclosed that its third-party fulfillment partner ShipMonk suffered a data breach that exposed personal data for 13,689 hardware wallet customers, including names, email addresses, phone numbers, and home shipping addresses. The breach originated from an unpatched critical SQL injection vulnerability (CVE-2026-72898) in Metabase, a business-intelligence tool used by ShipMonk. Trezor's own systems, hardware wallet firmware, and customer private keys were not affected, but the exposure of verified hardware wallet owner home addresses raises direct physical safety concerns given a documented surge in violent crypto-targeted home invasions in 2026.","sections":[{"content":"On August 10, 2026, ShipMonk — a third-party logistics and fulfillment provider used by Trezor — alerted Trezor that an unauthorized party had accessed customer order data held in ShipMonk's systems. Trezor publicly disclosed the breach on August 13, 2026. The breach window covered orders fulfilled between May 10, 2026, and August 8, 2026. According to Trezor's official disclosure, 13,689 customers were affected across seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor stated: 'To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts.' Trezor noted that its 90-day data retention policy with fulfillment partners meant that older order records had already been deleted and were not in scope.","heading":"Incident Overview","sources":[{"url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident","name":"Trezor official blog: Recent customer data exposed in shipping provider incident","type":"official","credibility":1},{"url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/","name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","credibility":1},{"url":"https://www.teiss.co.uk/news/trezor-discloses-data-breach-affecting-nearly-14000-customers-after-shipping-partner-hack-17982","name":"teiss: Trezor discloses data breach affecting nearly 14,000 customers after shipping partner hack","type":"news_article","credibility":2}],"severity":"high"},{"content":"Of the 13,689 affected customers, 11,742 suffered full exposure: their name, email address, phone number, and home shipping address were all accessible to the unauthorized party. An additional 1,947 customers had partial exposure limited to name, city, and email address, with no phone number or street-level address compromised. The contents of parcels — which in Trezor's case would implicitly indicate hardware wallet ownership — were not included in the exposed records, though any person cross-referencing the ShipMonk dataset against Trezor as the shipper would be able to infer that affected customers are hardware wallet owners. Wallet firmware, seed phrases, private keys, and on-chain assets were entirely outside the scope of this breach.","heading":"Scope of Data Exposure","sources":[{"url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident","name":"Trezor official blog: Recent customer data exposed in shipping provider incident","type":"official","credibility":1},{"url":"https://www.rescana.com/post/trezor-data-breach-analysis-14-000-customers-exposed-in-shipmonk-metabase-sql-injection-incident","name":"Trezor Data Breach Analysis — Rescana","type":"research","credibility":2},{"url":"https://cryptoticker.io/en/trezor-shipmonk-data-breach-customer-addresses-leaked/","name":"Trezor Data Breach Exposes 13,689 Customers — CryptoTicker","type":"news_article","credibility":2}],"severity":"high"},{"content":"The unauthorized access was made possible by CVE-2026-72898, a critical unauthenticated SQL injection vulnerability in Metabase, an open-source business-intelligence and analytics platform that ShipMonk used as a third-party tool. The vulnerability, rated CVSS 10.0, resides in Metabase's password-reset functionality: specifically, the publicly accessible POST /api/session/reset_password endpoint failed to restrict undeclared fields in the request body, allowing a remote attacker to inject arbitrary SQL without prior authentication. A successful exploit grants administrator-level access to the Metabase instance and, by extension, all databases connected to it — in ShipMonk's case, customer order data. Metabase informed ShipMonk on August 6, 2026, that the vulnerability had been exploited. ShipMonk then notified Trezor on August 10, 2026. According to security researchers at Horizon3 and Bishop Fox, roughly 4,309 of approximately 11,000 discoverable self-hosted Metabase instances were potentially unpatched at the time of disclosure. Metabase has since issued patches across all affected release branches (versions 0.58 through 0.63.4 and their enterprise equivalents) and invalidated all active sessions on affected instances. The vulnerability was being actively exploited in the wild at the time of disclosure, according to reporting by The Hacker News.","heading":"Technical Breach Vector: CVE-2026-72898 (Metabase)","sources":[{"url":"https://www.offsec.com/blog/cve-2026-72898-2/","name":"CVE-2026-72898: Critical Metabase Unauthenticated SQL Injection — OffSec","type":"research","credibility":2},{"url":"https://horizon3.ai/attack-research/vulnerabilities/cve-2026-72898/","name":"Metabase SQL Injection CVE-2026-72898 — Horizon3","type":"research","credibility":2},{"url":"https://bishopfox.com/blog/critical-sql-injection-in-metabase-via-password-reset-cve-2026-72898","name":"Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898 — Bishop Fox","type":"research","credibility":2},{"url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html","name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — The Hacker News","type":"news_article","credibility":1},{"url":"https://www.rescana.com/post/trezor-data-breach-analysis-14-000-customers-exposed-in-shipmonk-metabase-sql-injection-incident","name":"Trezor Data Breach Analysis — Rescana","type":"research","credibility":2}],"severity":"critical"},{"content":"The exposure of home shipping addresses linked to confirmed hardware wallet purchases creates a threat vector beyond conventional phishing. Chainalysis documented that violent crypto-targeted attacks — including home invasions and kidnappings — resulted in more than $30 million in losses across 46 incidents in the first half of 2026 alone, following $41 million in losses across 72 incidents in 2025. Home invasions accounted for 37% of 2026 incidents. Chainalysis analysis noted that the vast majority of victims in affected countries were local residents rather than tourists — 93% in France, 82% in Brazil, 77% in the United States — a pattern consistent with pre-attack reconnaissance and data-driven targeting rather than opportunistic crime. The ShipMonk breach dataset provides exactly the type of record that would enable such reconnaissance: a list of named individuals at known residential addresses, each confirmed to have recently purchased hardware designed to store cryptocurrency. The 11,742 customers with full name, phone number, email, and street address exposure are at the highest physical risk. Cryptoslate reported that Trezor plans to introduce 'Anonymous Delivery' options including locker pickup and automatic data deletion, rolling out in the EU by September 2026 and the United States by year-end, in part as a direct response to this incident.","heading":"Physical Safety Risk: Verified Crypto Owner Home Addresses","sources":[{"url":"https://www.chainalysis.com/blog/violent-crypto-wrench-attacks-2026/","name":"Violent Wrench Attacks Targeting Crypto Holders — Chainalysis","type":"research","credibility":1},{"url":"https://decrypt.co/375014/crypto-wrench-attacks-30m-stolen-2026-chainalysis","name":"Crypto Wrench Attacks on Pace for Record Year as $30M Stolen in 2026 — Decrypt","type":"news_article","credibility":2},{"url":"https://cryptoslate.com/with-violent-crypto-home-invasions-surging-a-data-breach-exposing-over-10000-trezor-owners-puts-physical-safety-on-the-line/","name":"With violent crypto home invasions surging, a data breach exposing over 10,000 Trezor owners puts physical safety on the line — CryptoSlate","type":"news_article","credibility":2},{"url":"https://theblock.co/post/410984/more-than-30-million-stolen-in-violent-crypto-attacks-in-2026-as-france-emerges-as-wrench-attack-hotspot-chainalysis","name":"More than $30 million stolen in violent crypto attacks in 2026 — The Block","type":"news_article","credibility":1}],"severity":"critical"},{"content":"This is at least the second publicly disclosed data breach associated with Trezor's use of third-party service providers. In January 2024, Trezor disclosed that an unauthorized party accessed the third-party support portal it used, potentially exposing the contact details of up to 66,000 customers who had interacted with Trezor Support since December 2021. That breach exposed names and email addresses, and resulted in at least 41 customers being directly contacted by the attacker with requests for sensitive seed-phrase information. In both the 2024 and 2026 incidents, Trezor's core infrastructure and hardware wallet devices were confirmed unaffected, with the risk materializing entirely through third-party vendors. The recurrence suggests a systemic supply-chain risk concentration that is independent of Trezor's device security posture.","heading":"Trezor's Breach History and Third-Party Risk Pattern","sources":[{"url":"https://www.bleepingcomputer.com/news/security/trezor-support-site-breach-exposes-personal-data-of-66-000-customers/","name":"Trezor support site breach exposes personal data of 66,000 customers — BleepingComputer","type":"news_article","credibility":1},{"url":"https://blog.trezor.io/trezor-security-update-stay-vigilant-against-potential-phishing-attack-bb05015a21f8","name":"Trezor security alert: Stay vigilant against a potential phishing attack — Trezor Blog","type":"official","credibility":1},{"url":"https://www.teiss.co.uk/news/trezor-discloses-data-breach-affecting-nearly-14000-customers-after-shipping-partner-hack-17982","name":"teiss: Trezor discloses data breach affecting nearly 14,000 customers after shipping partner hack","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Following disclosure, ShipMonk secured the affected systems and retained outside information technology experts to conduct a forensic investigation. Metabase issued patches across all affected release branches and invalidated active sessions on affected instances. Trezor notified affected customers directly via email from the address security@trezor.io and advised them to be vigilant against phishing attempts, unsolicited contact claiming to be from Trezor, and any communications requesting seed phrases or private key information. Trezor emphasized that legitimate Trezor communications will never request a user's seed phrase. Trezor also announced plans to roll out 'Anonymous Delivery' options — including parcel locker pickup and automatic post-delivery data deletion — in the EU by September 2026 and in the United States by year-end. Customers who received hardware wallet orders between May 10, 2026, and August 8, 2026, should treat their home address as potentially known to threat actors and take appropriate physical security precautions.","heading":"Remediation and Affected Customer Guidance","sources":[{"url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident","name":"Trezor official blog: Recent customer data exposed in shipping provider incident","type":"official","credibility":1},{"url":"https://cryptoslate.com/with-violent-crypto-home-invasions-surging-a-data-breach-exposing-over-10000-trezor-owners-puts-physical-safety-on-the-line/","name":"With violent crypto home invasions surging — CryptoSlate","type":"news_article","credibility":2},{"url":"https://cybersecuritynews.com/trezor-shipmonk-data-breach/","name":"Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers — CybersecurityNews","type":"news_article","credibility":2}],"severity":"medium"}],"timeline":[{"date":"2024-01-17","event":"Trezor discloses a breach of its third-party support portal, potentially exposing contact details of up to 66,000 customers. Names and email addresses were exposed; at least 41 customers were subsequently targeted with seed-phrase phishing.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/trezor-support-site-breach-exposes-personal-data-of-66-000-customers/"},{"date":"2026-05-10","event":"Start of the order window affected by the ShipMonk breach. Trezor customer orders fulfilled by ShipMonk from this date onward are within scope.","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"date":"2026-08-06","event":"Metabase informs ShipMonk that CVE-2026-72898, a critical unauthenticated SQL injection in Metabase's password-reset endpoint, had been exploited by an unauthorized party to access data tied to ShipMonk's account.","source":"teiss / Rescana","source_url":"https://www.teiss.co.uk/news/trezor-discloses-data-breach-affecting-nearly-14000-customers-after-shipping-partner-hack-17982"},{"date":"2026-08-08","event":"End of the order window affected by the breach. Orders fulfilled by ShipMonk on behalf of Trezor after this date are not in scope.","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"date":"2026-08-10","event":"ShipMonk notifies Trezor of the unauthorized access. Trezor begins customer notification process. Affected customers receive an email from security@trezor.io.","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"date":"2026-08-13","event":"Trezor publicly discloses the breach via its official blog. Third-party press coverage begins, including CoinDesk and BleepingComputer.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/08/13/trezor-warns-14-000-users-after-fulfilment-partner-suffers-data-breach"},{"date":"2026-08-13","event":"Security researchers publish CVE-2026-72898 analyses (OffSec, Horizon3, Bishop Fox, Wiz, Halborn). Approximately 4,309 of ~11,000 discoverable self-hosted Metabase instances are reported as potentially unpatched.","source":"Horizon3 / Bishop Fox","source_url":"https://horizon3.ai/attack-research/vulnerabilities/cve-2026-72898/"}],"sources_used":[{"url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident","name":"Trezor official blog: Recent customer data exposed in shipping provider incident","type":"official","credibility":1},{"url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/","name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","credibility":1},{"url":"https://www.coindesk.com/tech/2026/08/13/trezor-warns-14-000-users-after-fulfilment-partner-suffers-data-breach","name":"Third-party breach exposes shipping addresses of 14,000 Trezor buyers — CoinDesk","type":"news_article","credibility":1},{"url":"https://www.teiss.co.uk/news/trezor-discloses-data-breach-affecting-nearly-14000-customers-after-shipping-partner-hack-17982","name":"teiss: Trezor discloses data breach affecting nearly 14,000 customers after shipping partner hack","type":"news_article","credibility":2},{"url":"https://cybersecuritynews.com/trezor-shipmonk-data-breach/","name":"Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers — CybersecurityNews","type":"news_article","credibility":2},{"url":"https://cryptoslate.com/with-violent-crypto-home-invasions-surging-a-data-breach-exposing-over-10000-trezor-owners-puts-physical-safety-on-the-line/","name":"With violent crypto home invasions surging, a data breach exposing over 10,000 Trezor owners puts physical safety on the line — CryptoSlate","type":"news_article","credibility":2},{"url":"https://www.chainalysis.com/blog/violent-crypto-wrench-attacks-2026/","name":"Violent Wrench Attacks Targeting Crypto Holders — Chainalysis","type":"research","credibility":1},{"url":"https://theblock.co/post/410984/more-than-30-million-stolen-in-violent-crypto-attacks-in-2026-as-france-emerges-as-wrench-attack-hotspot-chainalysis","name":"More than $30 million stolen in violent crypto attacks in 2026 — The Block","type":"news_article","credibility":1},{"url":"https://decrypt.co/375014/crypto-wrench-attacks-30m-stolen-2026-chainalysis","name":"Crypto Wrench Attacks on Pace for Record Year as $30M Stolen in 2026 — Decrypt","type":"news_article","credibility":2},{"url":"https://www.offsec.com/blog/cve-2026-72898-2/","name":"CVE-2026-72898: Critical Metabase Unauthenticated SQL Injection — OffSec","type":"research","credibility":2},{"url":"https://horizon3.ai/attack-research/vulnerabilities/cve-2026-72898/","name":"Metabase SQL Injection CVE-2026-72898 — Horizon3","type":"research","credibility":2},{"url":"https://bishopfox.com/blog/critical-sql-injection-in-metabase-via-password-reset-cve-2026-72898","name":"Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898 — Bishop Fox","type":"research","credibility":2},{"url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html","name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — The Hacker News","type":"news_article","credibility":1},{"url":"https://www.rescana.com/post/trezor-data-breach-analysis-14-000-customers-exposed-in-shipmonk-metabase-sql-injection-incident","name":"Trezor Data Breach Analysis: ShipMonk Metabase SQL Injection — Rescana","type":"research","credibility":2},{"url":"https://www.bleepingcomputer.com/news/security/trezor-support-site-breach-exposes-personal-data-of-66-000-customers/","name":"Trezor support site breach exposes personal data of 66,000 customers — BleepingComputer","type":"news_article","credibility":1},{"url":"https://blog.trezor.io/trezor-security-update-stay-vigilant-against-potential-phishing-attack-bb05015a21f8","name":"Trezor security alert: Stay vigilant against a potential phishing attack — Trezor Blog","type":"official","credibility":1},{"url":"https://bitbo.io/news/trezor-shipmonk-data-breach/","name":"Trezor Data Breach Exposes 13,689 Customer Addresses — Bitbo","type":"news_article","credibility":3},{"url":"https://coinmarketcap.com/academy/article/trezor-shipmonk-breach-customer-data-phishing-risk","name":"ShipMonk Breach Puts Nearly 14K Trezor Customers at Phishing Risk — CoinMarketCap","type":"news_article","credibility":2}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-08-29T12:04:25.357876+00:00","updated_at":"2026-08-29T12:04:36.362+00:00"}}