ShipMonk
Summary
ShipMonk is a Fort Lauderdale-based third-party logistics and fulfillment provider founded in 2014 that serves e-commerce brands including crypto hardware wallet manufacturer Trezor. In August 2026, ShipMonk disclosed that an unauthorized party had exploited a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform deployed by ShipMonk, to access Trezor customer order data for at least 13,689 individuals. The exposed records — which include home shipping addresses, phone numbers, and email addresses of confirmed hardware wallet purchasers — carry elevated risk in a crypto context because they combine verified device ownership with physical location data.
Connected Entities
1 entities · 10 linked investigationsTimeline(8 events)
2026-05-10
Start of the breach window: orders placed from this date onward are within scope of the data accessed by the unauthorized party.
Trezor official blog2026-08-03
Metabase zero-day vulnerability reportedly detected; ShinyHunters later identified as having exploited the flaw across multiple organizations.
DigitalShield / Escudo Digital2026-08-06
Metabase publicly discloses the critical SQL injection zero-day (CVE-2026-72898, CVSS 10.0) and releases patches. Metabase notifies ShipMonk that an unauthorized party exploited the vulnerability to access customer data.
Help Net Security; Trezor official blog2026-08-08
End of the breach window: the last order date for which customer data was accessible to the unauthorized party.
Trezor official blog2026-08-10
ShipMonk notifies Trezor of the unauthorized access to customer order data.
Protos; CoinDesk2026-08-13
Trezor publicly discloses the breach, notifies 13,689 affected customers by email, and confirms ShipMonk as the source. Trezor states its own infrastructure and devices were not compromised.
CoinDesk; BleepingComputer; SecurityWeek2026-08-13
ShinyHunters lists Metabase on its dark-web leak site, claiming responsibility for the attack on the analytics platform.
SecurityWeek; Cybernews2026-08-14
ShipMonk has not issued a public statement acknowledging the breach. No regulatory actions, lawsuits, or criminal charges publicly reported as of this date.
SecurityWeekDecision Log
- #1publish⛓ pending8/14/2026, 5:05:18 PMhash: 8ZPp3R4gBExSVerid28HdmBG7ti6MFq2cobuJ4d9Uu3H
4 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/14/2026, 5:05:07 PM
last updated: 8/14/2026, 6:12:35 PM
avoid.net — verified advice for a post-truth world