← ShipMonk1 decision on this page
Audit log
Every state-changing event for ShipMonk: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-14 17:05:18ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
8ZPp3R4gBExS…J4d9Uu3Hsha256 → base58
verifying row…canonical bytes (22543 B) ▸
{"actor":"system:backfill","investigation_id":"930d9ec3-3b01-456d-b86e-c788baabbe19","kind":"publish","page_slug":"shipmonk","published_at":"2026-08-14T17:05:18.157Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"ShipMonk","sections":[{"content":"ShipMonk was founded in 2014 and is headquartered in Fort Lauderdale, Florida. The company describes itself as a technology-driven third-party logistics (3PL) provider specializing in fulfillment for direct-to-consumer, B2B, and retail e-commerce brands. ShipMonk operates more than 12 fulfillment centers across the United States, Canada, Mexico, and Europe and employs more than 1,000 staff. The company has been named to the Inc. 5000 list of fastest-growing U.S. companies. In its capacity as a logistics partner, ShipMonk stores inventory and ships parcels on behalf of its clients, holding customer name, address, phone, and order data required for delivery. Trezor, the Prague-based hardware wallet manufacturer, contracted ShipMonk to fulfill orders in the US, UK, and several other markets.","heading":"Company Overview","severity":"low","sources":[{"credibility":2,"name":"ShipMonk Inc. 5000 profile","type":"other","url":"https://www.inc.com/profile/shipmonk"},{"credibility":2,"name":"ShipMonk company profile — CBInsights","type":"other","url":"https://www.cbinsights.com/company/shipmonk"}]},{"content":"On August 6, 2026, Metabase — a business intelligence and data analytics platform — publicly disclosed a critical SQL injection zero-day vulnerability affecting its self-hosted and cloud deployments. The vulnerability, later assigned CVE-2026-72898 with a CVSS score of 10.0, resides in the /api/session/reset_password endpoint and allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, gaining administrator-level access without any credentials. Metabase confirmed the flaw was actively exploited in the wild and released patches for affected versions, which spanned v1.58.0 through v1.63.3. ShipMonk deployed Metabase as an analytics platform within its infrastructure. According to ShipMonk's notification to customers, on August 6, 2026, Metabase informed ShipMonk that an unauthorized party had exploited the vulnerability in Metabase's software to access data related to ShipMonk's accounts and its clients' customers. The extortion group ShinyHunters subsequently claimed responsibility for attacking Metabase and listed Metabase on its dark-web leak site. ShinyHunters is a financially motivated criminal extortion group operating a pay-or-leak model that has been active since 2019; the group's claim has not been independently verified by law enforcement as of the date of this report. Metabase instructed all self-hosted customers to upgrade to patched versions, revoke all active sessions, rotate credentials, review API keys and admin accounts, and audit database and activity logs for unauthorized access.","heading":"Breach Overview: Metabase SQL Injection Zero-Day","severity":"critical","sources":[{"credibility":1,"name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/"},{"credibility":1,"name":"Metabase zero-day exploited to access Framework, Tally customer data — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/"},{"credibility":1,"name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html"},{"credibility":1,"name":"14,000 Trezor Customers Impacted by Data Breach at ShipMonk — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"},{"credibility":2,"name":"ShinyHunters claims Metabase hack — Cybernews","type":"news_article","url":"https://cybernews.com/security/shinyhunters-metabase-hack-zero-day/"},{"credibility":2,"name":"Metabase hacked in major breach affecting more than 100,000 companies — DigitalShield / Escudo Digital","type":"news_article","url":"https://www.escudodigital.com/en/cybersecurity/metabase-hacked-in-major-breach-affecting-more-than-100000-companies.html"}]},{"content":"ShipMonk's breach exposed order data for 13,689 confirmed Trezor customers who received shipments between May 10 and August 8, 2026, across seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Of those, 11,742 customers had full records exposed — including full name, email address, phone number, and complete shipping (home) address. A further 1,947 customers had partial records exposed — name, city, and email address only. Order numbers were also accessible. Trezor confirmed that Amazon-fulfilled orders were not affected. No payment card data, wallet private keys, seed phrases, device firmware, or Trezor platform credentials were exposed. ShipMonk had not publicly acknowledged the incident as of the date of initial reporting; all public disclosure came via Trezor's own communications. Trezor stated that it is evaluating whether to continue its partnership with ShipMonk.","heading":"Scope of Exposed Customer Data","severity":"high","sources":[{"credibility":1,"name":"Recent customer data exposed in shipping provider incident — Trezor official blog","type":"official","url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"credibility":1,"name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/"},{"credibility":2,"name":"Trezor says 13,689 customers hit by data breach at shipping partner — Protos","type":"news_article","url":"https://protos.com/trezor-says-13689-customers-hit-by-data-breach-at-shipping-partner/"},{"credibility":1,"name":"Third-party breach exposes shipping addresses of 14,000 Trezor buyers — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/13/trezor-warns-14-000-users-after-fulfilment-partner-suffers-data-breach"}]},{"content":"The nature of Trezor's customer base makes this breach qualitatively more dangerous than a typical e-commerce data leak. Hardware wallet purchasers are, by definition, confirmed holders of cryptocurrency who have taken steps to secure it with dedicated hardware. The combination of verified hardware wallet ownership and a confirmed home shipping address creates a profile that is of direct operational value to criminals planning physical coercion or targeted robbery — a threat category sometimes referred to as the '$5 wrench attack.' Trezor warned its affected customers of elevated risk from phishing via email, phone, and physical mail, including fraudulent communications impersonating Trezor or financial institutions. Historical precedent supports this concern: prior hardware wallet data leaks — notably the Ledger breach of 2020, which affected approximately 270,000 customers — were subsequently linked to phishing campaigns, counterfeit device shipments, and documented extortion demands. The Trezor 2026 breach is the first incident in the company's 13-year history to expose customer phone numbers and residential addresses at scale.","heading":"Elevated Physical Risk to Crypto Hardware Wallet Owners","severity":"critical","sources":[{"credibility":1,"name":"Recent customer data exposed in shipping provider incident — Trezor official blog","type":"official","url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"credibility":1,"name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/"},{"credibility":2,"name":"Trezor Customer Data Exposed in Shipping Partner Breach — Decrypt","type":"news_article","url":"https://decrypt.co/375556/trezor-customer-data-exposed-in-shipping-partner-breach"}]},{"content":"The root cause of the ShipMonk breach was a zero-day vulnerability in Metabase, a third-party analytics tool that ShipMonk deployed within its infrastructure. The vulnerability was exploited before a patch was available, meaning ShipMonk could not have applied a vendor-supplied fix in advance. However, several systemic vendor risk management questions remain open. First, it is unknown when ShipMonk deployed the affected Metabase version and whether it had network-level controls limiting the platform's access to customer data. Second, the breadth of data accessible through the Metabase analytics layer — including full names, phone numbers, and physical delivery addresses for multiple clients' customers — raises questions about the principle of least privilege and data minimization in ShipMonk's analytics configuration. Third, ShipMonk had not issued any public statement acknowledging the breach as of the date of reporting; all customer notification was conducted by Trezor. The same Metabase zero-day was also exploited against Framework (a laptop manufacturer), Tally (a form-building platform), n8n (a workflow automation platform), and Kilo Code (an AI coding tool), indicating a broad, coordinated campaign across Metabase's customer base rather than an attack targeting ShipMonk specifically. Whether other ShipMonk fulfillment clients beyond Trezor had customer data accessed has not been publicly disclosed.","heading":"Vendor Risk Management and Root Cause Analysis","severity":"high","sources":[{"credibility":1,"name":"Metabase zero-day exploited to access Framework, Tally customer data — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/"},{"credibility":1,"name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html"},{"credibility":1,"name":"14,000 Trezor Customers Impacted by Data Breach at ShipMonk — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"},{"credibility":2,"name":"Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardware Wallet Customers — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/trezor-provider-shipmonk-breach-exposed-order-data-for-13689-hardware-wallet-customers/"}]},{"content":"Several factors limit the scope of the incident relative to a worst-case scenario. Trezor maintains a contractually required 90-day data retention and deletion policy with its fulfillment partners, under which ShipMonk was obligated to delete or anonymize order data 90 days after delivery. This policy bounded the accessible window to orders between May 10 and August 8, 2026, and meant that older customer records were no longer held in ShipMonk's systems at the time of the breach. Trezor's own infrastructure — including its website, firmware update servers, device supply chain, and customer account databases — was not compromised. Private keys, seed phrases, and cryptographic assets are not transmitted to or stored by fulfillment partners, and none were at risk. No confirmed cases of the exposed data being actively published for sale or used in targeted attacks had emerged as of the initial public disclosure date. Trezor announced plans to offer an 'Anonymous Delivery' option as a future mitigation measure, targeted for the EU by September 2026 and the US by the end of 2026.","heading":"Mitigating Factors","severity":"medium","sources":[{"credibility":1,"name":"Recent customer data exposed in shipping provider incident — Trezor official blog","type":"official","url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"credibility":1,"name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/"}]},{"content":"The ShipMonk breach is one node in a larger supply-chain attack campaign exploiting the Metabase zero-day. Metabase is used by more than 100,000 organizations across more than 150 countries as a business intelligence and analytics platform. ShinyHunters listed Metabase on its dark-web leak site after the disclosure, though the listing at the time of reporting lacked a detailed description of the total data volume stolen. Framework, a modular laptop manufacturer, confirmed that customer names, email addresses, phone numbers, postal addresses, and login IP addresses were accessed via the same vulnerability. Tally, a form-building platform, reported compromised email addresses and password hashes. n8n, a workflow automation platform, confirmed unauthorized access to 136 customer records including bcrypt-hashed passwords for five cloud accounts. Kilo Code confirmed exposure of Slack integration tokens, which were invalidated immediately. These disclosures collectively indicate that the Metabase vulnerability was exploited in a multi-target campaign before Metabase's disclosure and patching on August 6, 2026. The full scope of organizations affected — and whether additional ShipMonk clients are among them — remains under investigation.","heading":"Broader Metabase Supply Chain Campaign","severity":"high","sources":[{"credibility":1,"name":"Metabase zero-day exploited to access Framework, Tally customer data — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/"},{"credibility":2,"name":"Metabase hacked in major breach affecting more than 100,000 companies — DigitalShield / Escudo Digital","type":"news_article","url":"https://www.escudodigital.com/en/cybersecurity/metabase-hacked-in-major-breach-affecting-more-than-100000-companies.html"},{"credibility":1,"name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html"}]},{"content":"As of August 14, 2026, no regulatory enforcement actions, fines, class-action lawsuits, or criminal charges related to the ShipMonk breach have been publicly reported. The breach involved customers across multiple jurisdictions including the United States, the United Kingdom, and several EU member states (Sweden, Italy), meaning potential exposure to data protection frameworks including the EU General Data Protection Regulation (GDPR), the UK GDPR, and relevant U.S. state breach notification laws. Regulatory investigations under these frameworks are possible but had not been announced at the time of this report. ShipMonk had not issued any public statement acknowledging the incident as of August 14, 2026. This page will require updating as regulatory, legal, or law enforcement developments emerge.","heading":"Regulatory and Legal Status","severity":"medium","sources":[{"credibility":1,"name":"14,000 Trezor Customers Impacted by Data Breach at ShipMonk — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"},{"credibility":2,"name":"Trezor says 13,689 customers hit by data breach at shipping partner — Protos","type":"news_article","url":"https://protos.com/trezor-says-13689-customers-hit-by-data-breach-at-shipping-partner/"}]}],"sources_used":[{"credibility":1,"name":"Recent customer data exposed in shipping provider incident — Trezor official blog","type":"official","url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"credibility":1,"name":"Trezor discloses data breach affecting nearly 14,000 customers — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/"},{"credibility":1,"name":"14,000 Trezor Customers Impacted by Data Breach at ShipMonk — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"},{"credibility":1,"name":"Third-party breach exposes shipping addresses of 14,000 Trezor buyers — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/13/trezor-warns-14-000-users-after-fulfilment-partner-suffers-data-breach"},{"credibility":1,"name":"Metabase zero-day exploited to access Framework, Tally customer data — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/"},{"credibility":1,"name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html"},{"credibility":2,"name":"Trezor says 13,689 customers hit by data breach at shipping partner — Protos","type":"news_article","url":"https://protos.com/trezor-says-13689-customers-hit-by-data-breach-at-shipping-partner/"},{"credibility":2,"name":"Trezor Customer Data Exposed in Shipping Partner Breach — Decrypt","type":"news_article","url":"https://decrypt.co/375556/trezor-customer-data-exposed-in-shipping-partner-breach"},{"credibility":2,"name":"Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardware Wallet Customers — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/trezor-provider-shipmonk-breach-exposed-order-data-for-13689-hardware-wallet-customers/"},{"credibility":2,"name":"Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/trezor-shipmonk-data-breach/"},{"credibility":2,"name":"ShipMonk Data Breach Exposes 14,000 Trezor Customers — Blockonomi","type":"news_article","url":"https://blockonomi.com/shipmonk-data-breach-exposes-14000-trezor-customers-what-you-need-to-know/"},{"credibility":2,"name":"Metabase hacked in major breach affecting more than 100,000 companies — DigitalShield / Escudo Digital","type":"news_article","url":"https://www.escudodigital.com/en/cybersecurity/metabase-hacked-in-major-breach-affecting-more-than-100000-companies.html"},{"credibility":2,"name":"ShinyHunters claims Metabase hack — Cybernews","type":"news_article","url":"https://cybernews.com/security/shinyhunters-metabase-hack-zero-day/"},{"credibility":2,"name":"Trezor Data Breach Exposes 13,689 Customer Addresses — Bitbo","type":"news_article","url":"https://bitbo.io/news/trezor-shipmonk-data-breach/"},{"credibility":2,"name":"ShipMonk Inc. 5000 profile — Inc. Magazine","type":"other","url":"https://www.inc.com/profile/shipmonk"}],"summary":"ShipMonk is a Fort Lauderdale-based third-party logistics and fulfillment provider founded in 2014 that serves e-commerce brands including crypto hardware wallet manufacturer Trezor. In August 2026, ShipMonk disclosed that an unauthorized party had exploited a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform deployed by ShipMonk, to access Trezor customer order data for at least 13,689 individuals. The exposed records — which include home shipping addresses, phone numbers, and email addresses of confirmed hardware wallet purchasers — carry elevated risk in a crypto context because they combine verified device ownership with physical location data.","timeline":[{"date":"2026-05-10","event":"Start of the breach window: orders placed from this date onward are within scope of the data accessed by the unauthorized party.","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"date":"2026-08-03","event":"Metabase zero-day vulnerability reportedly detected; ShinyHunters later identified as having exploited the flaw across multiple organizations.","source":"DigitalShield / Escudo Digital","source_url":"https://www.escudodigital.com/en/cybersecurity/metabase-hacked-in-major-breach-affecting-more-than-100000-companies.html"},{"date":"2026-08-06","event":"Metabase publicly discloses the critical SQL injection zero-day (CVE-2026-72898, CVSS 10.0) and releases patches. Metabase notifies ShipMonk that an unauthorized party exploited the vulnerability to access customer data.","source":"Help Net Security; Trezor official blog","source_url":"https://www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/"},{"date":"2026-08-08","event":"End of the breach window: the last order date for which customer data was accessible to the unauthorized party.","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident"},{"date":"2026-08-10","event":"ShipMonk notifies Trezor of the unauthorized access to customer order data.","source":"Protos; CoinDesk","source_url":"https://protos.com/trezor-says-13689-customers-hit-by-data-breach-at-shipping-partner/"},{"date":"2026-08-13","event":"Trezor publicly discloses the breach, notifies 13,689 affected customers by email, and confirms ShipMonk as the source. Trezor states its own infrastructure and devices were not compromised.","source":"CoinDesk; BleepingComputer; SecurityWeek","source_url":"https://www.coindesk.com/tech/2026/08/13/trezor-warns-14-000-users-after-fulfilment-partner-suffers-data-breach"},{"date":"2026-08-13","event":"ShinyHunters lists Metabase on its dark-web leak site, claiming responsibility for the attack on the analytics platform.","source":"SecurityWeek; Cybernews","source_url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"},{"date":"2026-08-14","event":"ShipMonk has not issued a public statement acknowledging the breach. No regulatory actions, lawsuits, or criminal charges publicly reported as of this date.","source":"SecurityWeek","source_url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision c79d47d5-8b8b-4dd5-a3ff-f8f4f138dbbb
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.