← ShipMonk3 decisions on this page
Audit log
Every state-changing event for ShipMonk: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-14 17:05:18ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 443,507,544
- sig
4r8o7d2nZCmn…wwDBnKSoexplorer ↗- hash
8ZPp3R4gBExS…J4d9Uu3Hsha256 → base58
verifying row…full verify ↗canonical bytes (22543 B) ▸
{"actor":"system:backfill","investigation_id":"930d9ec3-3b01-456d-b86e-c788baabbe19","kind":"publish","page_slug":"shipmonk","published_at":"2026-08-14T17:05:18.157Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"ShipMonk","sections":[{"content":"ShipMonk was founded in 2014 and is headquartered in Fort Lauderdale, Florida. The company describes itself as a technology-driven third-party logistics (3PL) provider specializing in fulfillment for direct-to-consumer, B2B, and retail e-commerce brands. ShipMonk operates more than 12 fulfillment centers across the United States, Canada, Mexico, and Europe and employs more than 1,000 staff. The company has been named to the Inc. 5000 list of fastest-growing U.S. companies. In its capacity as a logistics partner, ShipMonk stores inventory and ships parcels on behalf of its clients, holding customer name, address, phone, and order data required for delivery. Trezor, the Prague-based hardware wallet manufacturer, contracted ShipMonk to fulfill orders in the US, UK, and several other markets.","heading":"Company Overview","severity":"low","sources":[{"credibility":2,"name":"ShipMonk Inc. 5000 profile","type":"other","url":"https://www.inc.com/profile/shipmonk"},{"credibility":2,"name":"ShipMonk company profile — CBInsights","type":"other","url":"https://www.cbinsights.com/company/shipmonk"}]},{"content":"On August 6, 2026, Metabase — a business intelligence and data analytics platform — publicly disclosed a critical SQL injection zero-day vulnerability affecting its self-hosted and cloud deployments. The vulnerability, later assigned CVE-2026-72898 with a CVSS score of 10.0, resides in the /api/session/reset_password endpoint and allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, gaining administrator-level access without any credentials. Metabase confirmed the flaw was actively exploited in the wild and released patches for affected versions, which spanned v1.58.0 through v1.63.3. ShipMonk deployed Metabase as an analytics platform within its infrastructure. According to ShipMonk's notification to customers, on August 6, 2026, Metabase informed ShipMonk that an unauthorized party had exploited the vulnerability in Metabase's software to access data related to ShipMonk's accounts and its clients' customers. The extortion group ShinyHunters subsequently claimed responsibility for attacking Metabase and listed Metabase on its dark-web leak site. ShinyHunters is a financially motivated criminal extortion group operating a pay-or-leak model that has been active since 2019; the group's claim has not been independently verified by law enforcement as of the date of this report. Metabase instructed all self-hosted customers to upgrade to patched versions, revoke all active sessions, rotate credentials, review API keys and admin accounts, and audit database and activity logs for unauthorized access.","heading":"Breach Overview: Metabase SQL Injection Zero-Day","severity":"critical","sources":[{"credibility":1,"name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/"},{"credibility":1,"name":"Metabase zero-day exploited to access Framework, Tally customer data — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/"},{"credibility":1,"name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html"},{"credibility":1,"name":"14,000 Trezor Customers Impacted by Data Breach at ShipMonk — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"},{"credibility":2,"name":"ShinyHunters claims Metabase hack — Cybernews","type":"news_article","url":"https://cybernews.com/security/shinyhunters-metabase-hack-zero-day/"},{"credibility":2,"name":"Metabase hacked in major breach affecting more than 100,000 companies — DigitalShield / Escudo Digital","type":"news_article","url":"https://www.escudodigital.com/en/cybersecurity/metabase-hacked-in-major-breach-affecting-more-than-100000-companies.html"}]},{"content":"ShipMonk's breach exposed order data for 13,689 confirmed Trezor customers who received shipments between May 10 and August 8, 2026, across seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Of those, 11,742 customers had full records exposed — including full name, email address, phone number, and complete shipping (home) address. A further 1,947 customers had partial records exposed — name, city, and email address only. Order numbers were also accessible. Trezor confirmed that Amazon-fulfilled orders were not affected. No payment card data, wallet private keys, seed phrases, device firmware, or Trezor platform credentials were exposed. ShipMonk had not publicly acknowledged the incident as of the date of initial reporting; all public disclosure came via Trezor's own communications. Trezor stated that it is evaluating whether to continue its partnership with ShipMonk.","heading":"Scope of Exposed Customer Data","severity":"high","sources":[{"credibility":1,"name":"Recent customer data exposed in shipping provider incident — Trezor official blog","type":"official","url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"credibility":1,"name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/"},{"credibility":2,"name":"Trezor says 13,689 customers hit by data breach at shipping partner — Protos","type":"news_article","url":"https://protos.com/trezor-says-13689-customers-hit-by-data-breach-at-shipping-partner/"},{"credibility":1,"name":"Third-party breach exposes shipping addresses of 14,000 Trezor buyers — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/13/trezor-warns-14-000-users-after-fulfilment-partner-suffers-data-breach"}]},{"content":"The nature of Trezor's customer base makes this breach qualitatively more dangerous than a typical e-commerce data leak. Hardware wallet purchasers are, by definition, confirmed holders of cryptocurrency who have taken steps to secure it with dedicated hardware. The combination of verified hardware wallet ownership and a confirmed home shipping address creates a profile that is of direct operational value to criminals planning physical coercion or targeted robbery — a threat category sometimes referred to as the '$5 wrench attack.' Trezor warned its affected customers of elevated risk from phishing via email, phone, and physical mail, including fraudulent communications impersonating Trezor or financial institutions. Historical precedent supports this concern: prior hardware wallet data leaks — notably the Ledger breach of 2020, which affected approximately 270,000 customers — were subsequently linked to phishing campaigns, counterfeit device shipments, and documented extortion demands. The Trezor 2026 breach is the first incident in the company's 13-year history to expose customer phone numbers and residential addresses at scale.","heading":"Elevated Physical Risk to Crypto Hardware Wallet Owners","severity":"critical","sources":[{"credibility":1,"name":"Recent customer data exposed in shipping provider incident — Trezor official blog","type":"official","url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"credibility":1,"name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/"},{"credibility":2,"name":"Trezor Customer Data Exposed in Shipping Partner Breach — Decrypt","type":"news_article","url":"https://decrypt.co/375556/trezor-customer-data-exposed-in-shipping-partner-breach"}]},{"content":"The root cause of the ShipMonk breach was a zero-day vulnerability in Metabase, a third-party analytics tool that ShipMonk deployed within its infrastructure. The vulnerability was exploited before a patch was available, meaning ShipMonk could not have applied a vendor-supplied fix in advance. However, several systemic vendor risk management questions remain open. First, it is unknown when ShipMonk deployed the affected Metabase version and whether it had network-level controls limiting the platform's access to customer data. Second, the breadth of data accessible through the Metabase analytics layer — including full names, phone numbers, and physical delivery addresses for multiple clients' customers — raises questions about the principle of least privilege and data minimization in ShipMonk's analytics configuration. Third, ShipMonk had not issued any public statement acknowledging the breach as of the date of reporting; all customer notification was conducted by Trezor. The same Metabase zero-day was also exploited against Framework (a laptop manufacturer), Tally (a form-building platform), n8n (a workflow automation platform), and Kilo Code (an AI coding tool), indicating a broad, coordinated campaign across Metabase's customer base rather than an attack targeting ShipMonk specifically. Whether other ShipMonk fulfillment clients beyond Trezor had customer data accessed has not been publicly disclosed.","heading":"Vendor Risk Management and Root Cause Analysis","severity":"high","sources":[{"credibility":1,"name":"Metabase zero-day exploited to access Framework, Tally customer data — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/"},{"credibility":1,"name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html"},{"credibility":1,"name":"14,000 Trezor Customers Impacted by Data Breach at ShipMonk — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"},{"credibility":2,"name":"Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardware Wallet Customers — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/trezor-provider-shipmonk-breach-exposed-order-data-for-13689-hardware-wallet-customers/"}]},{"content":"Several factors limit the scope of the incident relative to a worst-case scenario. Trezor maintains a contractually required 90-day data retention and deletion policy with its fulfillment partners, under which ShipMonk was obligated to delete or anonymize order data 90 days after delivery. This policy bounded the accessible window to orders between May 10 and August 8, 2026, and meant that older customer records were no longer held in ShipMonk's systems at the time of the breach. Trezor's own infrastructure — including its website, firmware update servers, device supply chain, and customer account databases — was not compromised. Private keys, seed phrases, and cryptographic assets are not transmitted to or stored by fulfillment partners, and none were at risk. No confirmed cases of the exposed data being actively published for sale or used in targeted attacks had emerged as of the initial public disclosure date. Trezor announced plans to offer an 'Anonymous Delivery' option as a future mitigation measure, targeted for the EU by September 2026 and the US by the end of 2026.","heading":"Mitigating Factors","severity":"medium","sources":[{"credibility":1,"name":"Recent customer data exposed in shipping provider incident — Trezor official blog","type":"official","url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"credibility":1,"name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/"}]},{"content":"The ShipMonk breach is one node in a larger supply-chain attack campaign exploiting the Metabase zero-day. Metabase is used by more than 100,000 organizations across more than 150 countries as a business intelligence and analytics platform. ShinyHunters listed Metabase on its dark-web leak site after the disclosure, though the listing at the time of reporting lacked a detailed description of the total data volume stolen. Framework, a modular laptop manufacturer, confirmed that customer names, email addresses, phone numbers, postal addresses, and login IP addresses were accessed via the same vulnerability. Tally, a form-building platform, reported compromised email addresses and password hashes. n8n, a workflow automation platform, confirmed unauthorized access to 136 customer records including bcrypt-hashed passwords for five cloud accounts. Kilo Code confirmed exposure of Slack integration tokens, which were invalidated immediately. These disclosures collectively indicate that the Metabase vulnerability was exploited in a multi-target campaign before Metabase's disclosure and patching on August 6, 2026. The full scope of organizations affected — and whether additional ShipMonk clients are among them — remains under investigation.","heading":"Broader Metabase Supply Chain Campaign","severity":"high","sources":[{"credibility":1,"name":"Metabase zero-day exploited to access Framework, Tally customer data — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/"},{"credibility":2,"name":"Metabase hacked in major breach affecting more than 100,000 companies — DigitalShield / Escudo Digital","type":"news_article","url":"https://www.escudodigital.com/en/cybersecurity/metabase-hacked-in-major-breach-affecting-more-than-100000-companies.html"},{"credibility":1,"name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html"}]},{"content":"As of August 14, 2026, no regulatory enforcement actions, fines, class-action lawsuits, or criminal charges related to the ShipMonk breach have been publicly reported. The breach involved customers across multiple jurisdictions including the United States, the United Kingdom, and several EU member states (Sweden, Italy), meaning potential exposure to data protection frameworks including the EU General Data Protection Regulation (GDPR), the UK GDPR, and relevant U.S. state breach notification laws. Regulatory investigations under these frameworks are possible but had not been announced at the time of this report. ShipMonk had not issued any public statement acknowledging the incident as of August 14, 2026. This page will require updating as regulatory, legal, or law enforcement developments emerge.","heading":"Regulatory and Legal Status","severity":"medium","sources":[{"credibility":1,"name":"14,000 Trezor Customers Impacted by Data Breach at ShipMonk — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"},{"credibility":2,"name":"Trezor says 13,689 customers hit by data breach at shipping partner — Protos","type":"news_article","url":"https://protos.com/trezor-says-13689-customers-hit-by-data-breach-at-shipping-partner/"}]}],"sources_used":[{"credibility":1,"name":"Recent customer data exposed in shipping provider incident — Trezor official blog","type":"official","url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"credibility":1,"name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/"},{"credibility":1,"name":"14,000 Trezor Customers Impacted by Data Breach at ShipMonk — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"},{"credibility":1,"name":"Third-party breach exposes shipping addresses of 14,000 Trezor buyers — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/13/trezor-warns-14-000-users-after-fulfilment-partner-suffers-data-breach"},{"credibility":1,"name":"Metabase zero-day exploited to access Framework, Tally customer data — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/"},{"credibility":1,"name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html"},{"credibility":2,"name":"Trezor says 13,689 customers hit by data breach at shipping partner — Protos","type":"news_article","url":"https://protos.com/trezor-says-13689-customers-hit-by-data-breach-at-shipping-partner/"},{"credibility":2,"name":"Trezor Customer Data Exposed in Shipping Partner Breach — Decrypt","type":"news_article","url":"https://decrypt.co/375556/trezor-customer-data-exposed-in-shipping-partner-breach"},{"credibility":2,"name":"Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardware Wallet Customers — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/trezor-provider-shipmonk-breach-exposed-order-data-for-13689-hardware-wallet-customers/"},{"credibility":2,"name":"Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/trezor-shipmonk-data-breach/"},{"credibility":2,"name":"ShipMonk Data Breach Exposes 14,000 Trezor Customers — Blockonomi","type":"news_article","url":"https://blockonomi.com/shipmonk-data-breach-exposes-14000-trezor-customers-what-you-need-to-know/"},{"credibility":2,"name":"Metabase hacked in major breach affecting more than 100,000 companies — DigitalShield / Escudo Digital","type":"news_article","url":"https://www.escudodigital.com/en/cybersecurity/metabase-hacked-in-major-breach-affecting-more-than-100000-companies.html"},{"credibility":2,"name":"ShinyHunters claims Metabase hack — Cybernews","type":"news_article","url":"https://cybernews.com/security/shinyhunters-metabase-hack-zero-day/"},{"credibility":2,"name":"Trezor Data Breach Exposes 13,689 Customer Addresses — Bitbo","type":"news_article","url":"https://bitbo.io/news/trezor-shipmonk-data-breach/"},{"credibility":2,"name":"ShipMonk Inc. 5000 profile — Inc. Magazine","type":"other","url":"https://www.inc.com/profile/shipmonk"}],"summary":"ShipMonk is a Fort Lauderdale-based third-party logistics and fulfillment provider founded in 2014 that serves e-commerce brands including crypto hardware wallet manufacturer Trezor. In August 2026, ShipMonk disclosed that an unauthorized party had exploited a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform deployed by ShipMonk, to access Trezor customer order data for at least 13,689 individuals. The exposed records — which include home shipping addresses, phone numbers, and email addresses of confirmed hardware wallet purchasers — carry elevated risk in a crypto context because they combine verified device ownership with physical location data.","timeline":[{"date":"2026-05-10","event":"Start of the breach window: orders placed from this date onward are within scope of the data accessed by the unauthorized party.","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"date":"2026-08-03","event":"Metabase zero-day vulnerability reportedly detected; ShinyHunters later identified as having exploited the flaw across multiple organizations.","source":"DigitalShield / Escudo Digital","source_url":"https://www.escudodigital.com/en/cybersecurity/metabase-hacked-in-major-breach-affecting-more-than-100000-companies.html"},{"date":"2026-08-06","event":"Metabase publicly discloses the critical SQL injection zero-day (CVE-2026-72898, CVSS 10.0) and releases patches. Metabase notifies ShipMonk that an unauthorized party exploited the vulnerability to access customer data.","source":"Help Net Security; Trezor official blog","source_url":"https://www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/"},{"date":"2026-08-08","event":"End of the breach window: the last order date for which customer data was accessible to the unauthorized party.","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"date":"2026-08-10","event":"ShipMonk notifies Trezor of the unauthorized access to customer order data.","source":"Protos; CoinDesk","source_url":"https://protos.com/trezor-says-13689-customers-hit-by-data-breach-at-shipping-partner/"},{"date":"2026-08-13","event":"Trezor publicly discloses the breach, notifies 13,689 affected customers by email, and confirms ShipMonk as the source. Trezor states its own infrastructure and devices were not compromised.","source":"CoinDesk; BleepingComputer; SecurityWeek","source_url":"https://www.coindesk.com/tech/2026/08/13/trezor-warns-14-000-users-after-fulfilment-partner-suffers-data-breach"},{"date":"2026-08-13","event":"ShinyHunters lists Metabase on its dark-web leak site, claiming responsibility for the attack on the analytics platform.","source":"SecurityWeek; Cybernews","source_url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"},{"date":"2026-08-14","event":"ShipMonk has not issued a public statement acknowledging the breach. No regulatory actions, lawsuits, or criminal charges publicly reported as of this date.","source":"SecurityWeek","source_url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision c79d47d5-8b8b-4dd5-a3ff-f8f4f138dbbb - #2reviewby reviewerreviewer2026-08-25 14:05:38ZScore: 28 → 28 (no score change)The page's factual core — the Metabase CVE-2026-72898 zero-day, the ShipMonk/Trezor breach scope (13,689 customers, 11,742 full/1,947 partial records), the related Framework/Tally/n8n/Kilo Code disclosures, and the mitigating 90-day retention policy — is well supported by primary and independent secondary sources, including Trezor's own blog. The most significant defect is an internal contradiction: the summary states ShipMonk 'disclosed' the breach, while the page's own body sections correctly note ShipMonk never issued any public statement and all disclosure came from Trezor. One cited source (CBInsights) also contradicts the page's stated 2014 founding year. The larger structural concern is that ShipMonk, an uninvolved logistics company with no independent crypto business, is included in a crypto risk index based solely on being one of several victims of a broad, non-crypto-specific supply-chain attack, with no source establishing negligence or misconduct on ShipMonk's part.anchoranchored
- chain
- ●mainnet-betaslot 443,515,069
- sig
63r9nz4cgM37…UBKKu7Cyexplorer ↗- hash
8QGMHRQD6Pro…vv4rMijDsha256 → base58
verifying row…full verify ↗canonical bytes (1336 B) ▸
{"actor":"reviewer","decided_at":"2026-08-25T14:05:37.763Z","decision":"review","investigation_id":"930d9ec3-3b01-456d-b86e-c788baabbe19","new_score":28,"page_slug":"shipmonk","prev_score":28,"reason":"The page's factual core — the Metabase CVE-2026-72898 zero-day, the ShipMonk/Trezor breach scope (13,689 customers, 11,742 full/1,947 partial records), the related Framework/Tally/n8n/Kilo Code disclosures, and the mitigating 90-day retention policy — is well supported by primary and independent secondary sources, including Trezor's own blog. The most significant defect is an internal contradiction: the summary states ShipMonk 'disclosed' the breach, while the page's own body sections correctly note ShipMonk never issued any public statement and all disclosure came from Trezor. One cited source (CBInsights) also contradicts the page's stated 2014 founding year. The larger structural concern is that ShipMonk, an uninvolved logistics company with no independent crypto business, is included in a crypto risk index based solely on being one of several victims of a broad, non-crypto-specific supply-chain attack, with no source establishing negligence or misconduct on ShipMonk's part.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 695f26f6-1130-4901-8cd0-f9e72a6f94c9 - #3review reviseby judgejudge2026-08-25 14:05:38ZScore: 28 → 16 (-12)The reviewer confirmed 20 of 24 claims outright and found only 1 disputed and 1 unverifiable, putting disputed_pct at 8.3% — mathematically inside the approve range, and the breach's core facts (the CVE, the 13,689-customer scope, the 90-day retention mitigation, and the parallel Framework/Tally/n8n/Kilo Code disclosures) are solidly confirmed against Trezor's own blog and multiple Tier-1 outlets. Two problems keep this out of approval anyway. First, the page's summary — its most-read line — says ShipMonk 'disclosed' the breach, which claim_findings[1] shows is false and contradicted by the page's own body sections and by Tier-1 sources: only Trezor ever made a public statement. A citation for the founding year (claim_findings[0]) also points to a CBInsights page that states a different year than the one claimed. Second, and more consequential, the reviewer flagged a high-priority coverage gap: ShipMonk is a non-crypto logistics company caught up in a broad, unrelated Metabase zero-day that hit several other unrelated companies too, and no source establishes any fault or misconduct on ShipMonk's part, yet the page's 'vendor risk management' section (claim_findings[22]) frames open questions in a way that risks implying an unproven governance failure. That is an aggregate framing problem, not a false-statement problem, and it is not something a disputed-claims percentage can measure — it requires the page to add plain, prominent context that ShipMonk itself is not a crypto business and is included solely as a third-party vendor, not because any source found it at fault. This revision request addresses correctable defects; it is not a judgment on whether ShipMonk should be indexed at all.anchoranchored
- chain
- ●mainnet-betaslot 443,515,080
- sig
Q3FemLR93R6t…y3XswJfzexplorer ↗- hash
7URqywFj1r9D…34w3ZW7Hsha256 → base58
verifying row…full verify ↗canonical bytes (2065 B) ▸
{"actor":"judge","decided_at":"2026-08-25T14:05:37.763Z","decision":"review_revise","investigation_id":"930d9ec3-3b01-456d-b86e-c788baabbe19","new_score":16,"page_slug":"shipmonk","prev_score":28,"reason":"The reviewer confirmed 20 of 24 claims outright and found only 1 disputed and 1 unverifiable, putting disputed_pct at 8.3% — mathematically inside the approve range, and the breach's core facts (the CVE, the 13,689-customer scope, the 90-day retention mitigation, and the parallel Framework/Tally/n8n/Kilo Code disclosures) are solidly confirmed against Trezor's own blog and multiple Tier-1 outlets. Two problems keep this out of approval anyway. First, the page's summary — its most-read line — says ShipMonk 'disclosed' the breach, which claim_findings[1] shows is false and contradicted by the page's own body sections and by Tier-1 sources: only Trezor ever made a public statement. A citation for the founding year (claim_findings[0]) also points to a CBInsights page that states a different year than the one claimed. Second, and more consequential, the reviewer flagged a high-priority coverage gap: ShipMonk is a non-crypto logistics company caught up in a broad, unrelated Metabase zero-day that hit several other unrelated companies too, and no source establishes any fault or misconduct on ShipMonk's part, yet the page's 'vendor risk management' section (claim_findings[22]) frames open questions in a way that risks implying an unproven governance failure. That is an aggregate framing problem, not a false-statement problem, and it is not something a disputed-claims percentage can measure — it requires the page to add plain, prominent context that ShipMonk itself is not a crypto business and is included solely as a third-party vendor, not because any source found it at fault. This revision request addresses correctable defects; it is not a judgment on whether ShipMonk should be indexed at all.","score_delta":-12,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 20c4714e-5c4c-443d-87a6-d8a6eaf3f0e7
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.