discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Trezor discloses data breach affecting nearly 14,000 customers

Hardware wallet maker Trezor disclosed a data breach affecting nearly 14,000 customers after its shipping provider ShipMonk was hacked via a Metabase vulnerability.

By Sergiu Gatlan·Aug 13·bleepingcomputer.com·3 min read

Intelligence analysis by Llama

Trezor discloses data breach affecting nearly 14,000 customers
Image: bleepingcomputer.com

Trezor disclosed a data breach affecting nearly 14,000 customers stemming from a hack on shipping provider ShipMonk. The breach exposed names, emails, phone numbers, and shipping addresses. Attackers exploited a Metabase zero-day vulnerability.

Why it matters

This breach underscores the supply-chain risk that hardware wallet manufacturers face, where a vulnerability in a third-party analytics or logistics platform can expose sensitive customer data. It also shows how stolen contact details become fuel for targeted phishing campaigns aimed at crypto holders.

Trezor makes little gadgets that keep cryptocurrency safe. Someone hacked the company that ships those gadgets and learned the names, emails, phone numbers, and addresses of about 14,000 customers. Now the crooks might try to trick those people into giving away the secret passwords that unlock their crypto.

Analysis

Metabase zero-day vulnerability

The breach at ShipMonk was enabled by a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform used by the logistics firm. ShipMonk told affected customers that on August 6, 2026, Metabase disclosed that an unauthorized party had exploited a flaw in the platform's software to access data. According to ShipMonk, the vendor has since patched the vulnerability and invalidated all active sessions, and the company initiated a technical investigation with external IT experts. BleepingComputer previously reported that threat actors used this Metabase zero-day to breach customer instances, gain administrator access, and carry out data theft attacks — a campaign that appears to extend well beyond a single victim.

ShipMonk as the attack vector

Trezor's own systems were not compromised, and the company stressed that all Trezor devices remain secure. The intrusion was entirely through ShipMonk, Trezor's shipping and logistics provider, which informed the hardware wallet vendor on August 10, 2026, of unauthorized access to systems containing customer data. Trezor said the incident affects 11,742 customers with full exposure of name, email, phone number, and shipping address, plus 1,947 customers with partial exposure of name, city, and email. The pattern echoes Trezor's January 2024 breach, when attackers compromised a third-party support ticketing portal — reinforcing how a hardware wallet company's security posture depends on the entire vendor chain, not just its own perimeter.

ShinyHunters and a wider victim pool

ShipMonk has since received extortion emails from the ShinyHunters extortion gang, the same group known for high-profile data-theft and extortion campaigns. The Metabase zero-day has not stopped at ShipMonk — laptop maker Framework and online form builder Tally have also notified customers of data breaches after their Metabase instances were hijacked, suggesting a coordinated operation. Trezor warned that exposed customers may see more sophisticated phishing attempts, including fake emails, fraudulent phone calls, bogus letters, and impersonations of banks, crypto exchanges, or Trezor itself. The company's 2024 breach led attackers to attempt stealing 24-word recovery seeds from victims, illustrating how contact data on crypto users is particularly high-value to fraudsters.

Key points

  • Trezor disclosed a data breach affecting 11,742 fully exposed and 1,947 partially exposed customers after logistics provider ShipMonk was hacked.
  • Attackers exploited a critical SQL injection zero-day in the Metabase analytics platform, which ShipMonk has since confirmed was patched.
  • Exposed data includes names, email addresses, phone numbers, and shipping addresses for customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
  • ShipMonk received extortion emails from the ShinyHunters gang, and other Metabase victims include Framework and Tally.
  • Trezor stressed that its own systems and devices were not compromised, but warned customers to expect targeted phishing and impersonation attempts.
The Upside

Metabase reportedly patched the vulnerability and invalidated active sessions, cutting off the attackers' initial access route. Trezor confirmed that its own systems were not compromised and that all devices remain secure, meaning customer funds and recovery seeds were not directly exposed.

The Downside

Trezor itself warned that affected customers may face more sophisticated phishing attempts using real names, addresses, and phone numbers to impersonate banks, crypto exchanges, or Trezor support. ShipMonk has already received extortion emails from the ShinyHunters gang, and the same Metabase zero-day hit other vendors including Framework and Tally, suggesting the stolen data may circulate widely among criminal groups.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycryptohardwarebusiness

Author

Sergiu Gatlan

Intelligence analysis by

Llama

Published

Aug 13, 2026

Source

bleepingcomputer.com

Share

Topics

securitycryptohardwarebusiness

Related

More from this desk

Aug 13·bleepingcomputer.com

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries.

Aug 13·bleepingcomputer.com

Who Vets AI's Code? The Scale Challenge Facing Open Source Ingestion

The article discusses the challenge of vetting AI code, particularly in open-source software, due to the rapid generation of dependencies by AI coding assistants. This has led to a vulnerability known as slopsquatting, where attackers register dummy package names on publi…

Aug 13·bleepingcomputer.com

White House Taps Security Firms for Offensive Hack-Back Operations

The White House has signed a national security presidential memorandum that enables private security companies to apply for approval to hack foreign cybercrime organizations. The program will be overseen by executive directors designated by the Justice and Homeland Securi…

Siemens Parasolid Vulnerability Exposes Industrial Control Systems to Out-of-Bounds Read Attacks

Aug 13·cisa.gov

Siemens Parasolid Vulnerability Exposes Industrial Control Systems to Out-of-Bounds Read Attacks

Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected: Parasolid V38.0 vers:intdot/<38.0.235 (CVE-2026-64629) Parasolid V38.1 vers:intdot/<38.1.230 (CVE-2026-64…