Trezor discloses data breach affecting nearly 14,000 customers
Hardware wallet maker Trezor disclosed a data breach affecting nearly 14,000 customers after its shipping provider ShipMonk was hacked via a Metabase vulnerability.
Intelligence analysis by Llama

Trezor disclosed a data breach affecting nearly 14,000 customers stemming from a hack on shipping provider ShipMonk. The breach exposed names, emails, phone numbers, and shipping addresses. Attackers exploited a Metabase zero-day vulnerability.
Trezor makes little gadgets that keep cryptocurrency safe. Someone hacked the company that ships those gadgets and learned the names, emails, phone numbers, and addresses of about 14,000 customers. Now the crooks might try to trick those people into giving away the secret passwords that unlock their crypto.
Analysis
Metabase zero-day vulnerability
The breach at ShipMonk was enabled by a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform used by the logistics firm. ShipMonk told affected customers that on August 6, 2026, Metabase disclosed that an unauthorized party had exploited a flaw in the platform's software to access data. According to ShipMonk, the vendor has since patched the vulnerability and invalidated all active sessions, and the company initiated a technical investigation with external IT experts. BleepingComputer previously reported that threat actors used this Metabase zero-day to breach customer instances, gain administrator access, and carry out data theft attacks — a campaign that appears to extend well beyond a single victim.
ShipMonk as the attack vector
Trezor's own systems were not compromised, and the company stressed that all Trezor devices remain secure. The intrusion was entirely through ShipMonk, Trezor's shipping and logistics provider, which informed the hardware wallet vendor on August 10, 2026, of unauthorized access to systems containing customer data. Trezor said the incident affects 11,742 customers with full exposure of name, email, phone number, and shipping address, plus 1,947 customers with partial exposure of name, city, and email. The pattern echoes Trezor's January 2024 breach, when attackers compromised a third-party support ticketing portal — reinforcing how a hardware wallet company's security posture depends on the entire vendor chain, not just its own perimeter.
ShinyHunters and a wider victim pool
ShipMonk has since received extortion emails from the ShinyHunters extortion gang, the same group known for high-profile data-theft and extortion campaigns. The Metabase zero-day has not stopped at ShipMonk — laptop maker Framework and online form builder Tally have also notified customers of data breaches after their Metabase instances were hijacked, suggesting a coordinated operation. Trezor warned that exposed customers may see more sophisticated phishing attempts, including fake emails, fraudulent phone calls, bogus letters, and impersonations of banks, crypto exchanges, or Trezor itself. The company's 2024 breach led attackers to attempt stealing 24-word recovery seeds from victims, illustrating how contact data on crypto users is particularly high-value to fraudsters.
Key points
- Trezor disclosed a data breach affecting 11,742 fully exposed and 1,947 partially exposed customers after logistics provider ShipMonk was hacked.
- Attackers exploited a critical SQL injection zero-day in the Metabase analytics platform, which ShipMonk has since confirmed was patched.
- Exposed data includes names, email addresses, phone numbers, and shipping addresses for customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
- ShipMonk received extortion emails from the ShinyHunters gang, and other Metabase victims include Framework and Tally.
- Trezor stressed that its own systems and devices were not compromised, but warned customers to expect targeted phishing and impersonation attempts.
Metabase reportedly patched the vulnerability and invalidated active sessions, cutting off the attackers' initial access route. Trezor confirmed that its own systems were not compromised and that all devices remain secure, meaning customer funds and recovery seeds were not directly exposed.
Trezor itself warned that affected customers may face more sophisticated phishing attempts using real names, addresses, and phone numbers to impersonate banks, crypto exchanges, or Trezor support. ShipMonk has already received extortion emails from the ShinyHunters gang, and the same Metabase zero-day hit other vendors including Framework and Tally, suggesting the stolen data may circulate widely among criminal groups.


