Trezor (ShipMonk Data Breach)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
Summary
On August 10, 2026, Trezor disclosed that its third-party fulfillment partner ShipMonk suffered a data breach that exposed personal data for 13,689 hardware wallet customers, including names, email addresses, phone numbers, and home shipping addresses. The breach originated from an unpatched critical SQL injection vulnerability (CVE-2026-72898) in Metabase, a business-intelligence tool used by ShipMonk. Trezor's own systems, hardware wallet firmware, and customer private keys were not affected, but the exposure of verified hardware wallet owner home addresses raises direct physical safety concerns given a documented surge in violent crypto-targeted home invasions in 2026.
Connected Entities
1 entitiesTimeline(7 events)
17 January 2024
Trezor discloses a breach of its third-party support portal, potentially exposing contact details of up to 66,000 customers. Names and email addresses were exposed; at least 41 customers were subsequently targeted with seed-phrase phishing.
BleepingComputer10 May 2026
Start of the order window affected by the ShipMonk breach. Trezor customer orders fulfilled by ShipMonk from this date onward are within scope.
Trezor official blog6 August 2026
Metabase informs ShipMonk that CVE-2026-72898, a critical unauthenticated SQL injection in Metabase's password-reset endpoint, had been exploited by an unauthorized party to access data tied to ShipMonk's account.
teiss / Rescana8 August 2026
End of the order window affected by the breach. Orders fulfilled by ShipMonk on behalf of Trezor after this date are not in scope.
Trezor official blog10 August 2026
ShipMonk notifies Trezor of the unauthorized access. Trezor begins customer notification process. Affected customers receive an email from security@trezor.io.
Trezor official blog13 August 2026
Trezor publicly discloses the breach via its official blog. Third-party press coverage begins, including CoinDesk and BleepingComputer.
CoinDesk13 August 2026
Security researchers publish CVE-2026-72898 analyses (OffSec, Horizon3, Bishop Fox, Wiz, Halborn). Approximately 4,309 of ~11,000 discoverable self-hosted Metabase instances are reported as potentially unpatched.
Horizon3 / Bishop FoxDecision Log
- #1publish⛓ pending8/29/2026, 12:04:36 PMhash: 3DXSxLU9fh8dBvJ5C2d5uatk978M6KRNQyV2CTw8ESK4
0 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/29/2026, 12:04:25 PM
last updated: 8/29/2026, 12:04:36 PM
avoid.net — verified advice for a post-truth world