Skip to main content
Sign in

Trezor (ShipMonk Data Breach)

avoid.net/trezor-shipmonk-data-breach58/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

On August 10, 2026, Trezor disclosed that its third-party fulfillment partner ShipMonk suffered a data breach that exposed personal data for 13,689 hardware wallet customers, including names, email addresses, phone numbers, and home shipping addresses. The breach originated from an unpatched critical SQL injection vulnerability (CVE-2026-72898) in Metabase, a business-intelligence tool used by ShipMonk. Trezor's own systems, hardware wallet firmware, and customer private keys were not affected, but the exposure of verified hardware wallet owner home addresses raises direct physical safety concerns given a documented surge in violent crypto-targeted home invasions in 2026.

Connected Entities

1 entities
Organizations
Trezor (ShipMonk Data Breach)
Relationships
    Have evidence about Trezor (ShipMonk Data Breach)?

    Timeline(7 events)

    17 January 2024

    Trezor discloses a breach of its third-party support portal, potentially exposing contact details of up to 66,000 customers. Names and email addresses were exposed; at least 41 customers were subsequently targeted with seed-phrase phishing.

    BleepingComputer

    10 May 2026

    Start of the order window affected by the ShipMonk breach. Trezor customer orders fulfilled by ShipMonk from this date onward are within scope.

    Trezor official blog

    6 August 2026

    Metabase informs ShipMonk that CVE-2026-72898, a critical unauthenticated SQL injection in Metabase's password-reset endpoint, had been exploited by an unauthorized party to access data tied to ShipMonk's account.

    teiss / Rescana

    8 August 2026

    End of the order window affected by the breach. Orders fulfilled by ShipMonk on behalf of Trezor after this date are not in scope.

    Trezor official blog

    10 August 2026

    ShipMonk notifies Trezor of the unauthorized access. Trezor begins customer notification process. Affected customers receive an email from security@trezor.io.

    Trezor official blog

    13 August 2026

    Trezor publicly discloses the breach via its official blog. Third-party press coverage begins, including CoinDesk and BleepingComputer.

    CoinDesk

    13 August 2026

    Security researchers publish CVE-2026-72898 analyses (OffSec, Horizon3, Bishop Fox, Wiz, Halborn). Approximately 4,309 of ~11,000 discoverable self-hosted Metabase instances are reported as potentially unpatched.

    Horizon3 / Bishop Fox
    Provenance & Audit Trail

    Decision Log

    • #1publish⛓ pending8/29/2026, 12:04:36 PM
      hash: 3DXSxLU9fh8dBvJ5C2d5uatk978M6KRNQyV2CTw8ESK4

    0 of 18 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/29/2026, 12:04:25 PM

    last updated: 8/29/2026, 12:04:36 PM

    avoid.net — verified advice for a post-truth world