Skip to main content
AVOID.NET

ShipMonk

avoid.net/shipmonk→16/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4r8o7d…nKSo

Summary

ShipMonk is a Fort Lauderdale-based third-party logistics and fulfillment provider founded in 2014 that serves e-commerce brands including crypto hardware wallet manufacturer Trezor. In August 2026, ShipMonk disclosed that an unauthorized party had exploited a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform deployed by ShipMonk, to access Trezor customer order data for at least 13,689 individuals. The exposed records — which include home shipping addresses, phone numbers, and email addresses of confirmed hardware wallet purchasers — carry elevated risk in a crypto context because they combine verified device ownership with physical location data.

Connected Through

3 shared actors · 53 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about ShipMonk?

Timeline(8 events)

10 May 2026

Start of the breach window: orders placed from this date onward are within scope of the data accessed by the unauthorized party.

Trezor official blog

3 August 2026

Metabase zero-day vulnerability reportedly detected; ShinyHunters later identified as having exploited the flaw across multiple organizations.

DigitalShield / Escudo Digital

6 August 2026

Metabase publicly discloses the critical SQL injection zero-day (CVE-2026-72898, CVSS 10.0) and releases patches. Metabase notifies ShipMonk that an unauthorized party exploited the vulnerability to access customer data.

Help Net Security; Trezor official blog

8 August 2026

End of the breach window: the last order date for which customer data was accessible to the unauthorized party.

Trezor official blog

10 August 2026

ShipMonk notifies Trezor of the unauthorized access to customer order data.

Protos; CoinDesk

13 August 2026

Trezor publicly discloses the breach, notifies 13,689 affected customers by email, and confirms ShipMonk as the source. Trezor states its own infrastructure and devices were not compromised.

CoinDesk; BleepingComputer; SecurityWeek

13 August 2026

ShinyHunters lists Metabase on its dark-web leak site, claiming responsibility for the attack on the analytics platform.

SecurityWeek; Cybernews

14 August 2026

ShipMonk has not issued a public statement acknowledging the breach. No regulatory actions, lawsuits, or criminal charges publicly reported as of this date.

SecurityWeek
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 13 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/14/2026, 5:05:07 PM

last updated: 8/25/2026, 2:05:37 PM

4 views

avoid.net — verified advice for a post-truth world