ShipMonk
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4r8o7d…nKSoSummary
ShipMonk is a Fort Lauderdale-based third-party logistics and fulfillment provider founded in 2014 that serves e-commerce brands including crypto hardware wallet manufacturer Trezor. In August 2026, ShipMonk disclosed that an unauthorized party had exploited a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform deployed by ShipMonk, to access Trezor customer order data for at least 13,689 individuals. The exposed records — which include home shipping addresses, phone numbers, and email addresses of confirmed hardware wallet purchasers — carry elevated risk in a crypto context because they combine verified device ownership with physical location data.
Connected Entities
3 entities · 53 linked investigations- ShipMonk→mentioned with→Amazon(60%)
- ShipMonk→mentioned with→Trezor(80%)
Connected Through
3 shared actors · 53 investigationsDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- □Trezororganizationalso in$91M Bitcoin Social Engineering Theft — Hardware Wallet Impersonation (August 2026)·0AI-Powered Crypto Phishing Infrastructure 2026·0Fake Trezor Support Social Engineering — $282M Heist·0IRS Fake Digital Asset Compliance Portal Letter Campaign — 2026·0Tiffany Milanovich·0Patrick Yarmoch (FBI Agent — Crypto Theft)·0Patrick Steven Yaroch — FBI Agent Crypto Theft·0Fake Sparrow Wallet (Apple App Store)·0Coldcard Fake Hardware Audit Phishing Campaign·0Apple App Store — Systematic Fake Crypto Wallet Cluster (26 Apps, April 2026)·0CastleLoader / NeedleStealer Crypto Wallet Malware Campaign·0IRS Fake Digital Asset Compliance Portal — Physical Mail Phishing·0Socket Security Malicious Browser Extension Campaign August 2026·2Trenton Richard Johnston·2Trenton Johnston — Crypto Social Engineering Theft Ring·2Rublevka Team·2Coldcard / Coinkite Firmware Seed-Generation Exploit (July-August 2026)·3CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)·4Brandon Michael Tardibone·4Coldcard / Coinkite Hardware Wallet Firmware Exploit·6Coinkite·15Trezor Email Provider Breach (Brevo, September 2026)·22Shuffle (shuffle.com)·26Yield Guild Games (YGG)·30Brevo (email marketing platform used by Trezor, BitBox, CoinTracking, Solana Mobile)·32Brevo·42Bits of Gold·44Trezor (ShipMonk Data Breach)·46Trezor·57Electrum·62
- □Amazonorganizationalso inNicolo Nourafchan / Robert Yadgarov (SEC/DOJ Insider Trading Ring)·0Faris Ali / UK Crypto Home Invasion Ring·0ClickFix BNB Chain EtherHiding Malware Campaign·0Faris Ali·2GAW Miners / Josh Garza·2Mining Automatic (Zan Shaikh / Bright Vision Distribution LLC)·2Unicoin Inc.·4Grand Base·5Saddle Finance·10MELANIA Memecoin·12Term Labs·17Term Finance·22Roman Storm·22YO Protocol·42CoW Swap (CoW Protocol)·50HEEBOO·54Injective Protocol·55Scroll·58ThalaSwap·62Amazon·65Amazon Web Services·65Crossmint·70Orca·80
- □ShipMonkorganization
Timeline(8 events)
10 May 2026
Start of the breach window: orders placed from this date onward are within scope of the data accessed by the unauthorized party.
Trezor official blog3 August 2026
Metabase zero-day vulnerability reportedly detected; ShinyHunters later identified as having exploited the flaw across multiple organizations.
DigitalShield / Escudo Digital6 August 2026
Metabase publicly discloses the critical SQL injection zero-day (CVE-2026-72898, CVSS 10.0) and releases patches. Metabase notifies ShipMonk that an unauthorized party exploited the vulnerability to access customer data.
Help Net Security; Trezor official blog8 August 2026
End of the breach window: the last order date for which customer data was accessible to the unauthorized party.
Trezor official blog10 August 2026
ShipMonk notifies Trezor of the unauthorized access to customer order data.
Protos; CoinDesk13 August 2026
Trezor publicly discloses the breach, notifies 13,689 affected customers by email, and confirms ShipMonk as the source. Trezor states its own infrastructure and devices were not compromised.
CoinDesk; BleepingComputer; SecurityWeek13 August 2026
ShinyHunters lists Metabase on its dark-web leak site, claiming responsibility for the attack on the analytics platform.
SecurityWeek; Cybernews14 August 2026
ShipMonk has not issued a public statement acknowledging the breach. No regulatory actions, lawsuits, or criminal charges publicly reported as of this date.
SecurityWeekDecision Log
- hash: 7URqywFj1r9Dg917tFyuuiASxor6SUKQ7hCe34w3ZW7H
- hash: 8QGMHRQD6ProZ6jLwgiDJsuJXwsXymha7dHLvv4rMijD
- hash: 8ZPp3R4gBExSVerid28HdmBG7ti6MFq2cobuJ4d9Uu3H
This investigation is cryptographically anchored to the Solana blockchain (3 events). 13 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/14/2026, 5:05:07 PM
last updated: 8/25/2026, 2:05:37 PM
4 viewsavoid.net — verified advice for a post-truth world