SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach TREZOR-LOGISTICS-P 2026-08-15

Trezor: Third-Party Logistics Breach at ShipMonk

"Hardware wallet maker Trezor confirmed in an August 13, 2026 blog post that ShipMonk, one of its shipping and fulfillment providers, suffered a data breach exposing order data for roughly 13,689 customers across seven…"

Hardware wallet maker Trezor confirmed in an August 13, 2026 blog post that ShipMonk, one of its shipping and fulfillment providers, suffered a data breach exposing order data for roughly 13,689 customers across seven countries. Trezor says it was notified by ShipMonk on Monday, August 10, 2026. Headline counts vary by outlet: The Register reports "more than 13,000," BleepingComputer and SecurityWeek describe it as "nearly 14,000," and CoinDesk rounds to "14,000," but every source traces back to the same two Trezor-provided figures: 11,742 customers with full exposure and 1,947 with partial exposure, totalling 13,689. Trezor states its own systems, devices, private keys, and wallet backups were not affected.

What Happened

According to Trezor's own notice, ShipMonk informed the company on August 10 of unauthorized access to systems holding customer order data. ShipMonk is the logistics partner that warehouses Trezor products and ships parcels on the company's behalf, which is why it held recipient names, addresses, phone numbers, and emails at all: carriers require those fields to deliver a package.

Trezor's initial framing was that exposure was bounded by its 90-day data retention policy, which it says it negotiated into its fulfillment partners' contracts and which requires order data to be deleted or anonymized 90 days after collection. On that basis the affected window was given as orders received between May 10 and August 8, 2026, in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.

That boundary has since softened. Trezor appended an update to its blog stating that the 1,947 partially exposed customers "may include older orders," and that it is "verifying this information and the timeframe with ShipMonk." The Register picked this up as the key development: earlier orders outside the stated 90-day window may also be in scope. Trezor says it is in direct contact with ShipMonk to establish an exact timeline and full scope. The investigation is described as ongoing, and ShipMonk did not respond to The Register's request for comment.

What Was Taken

Two tiers of exposure, per Trezor and consistent across all eight sources:

CryptoPotato additionally reports that order numbers were included in the exposed records. That detail appears in only one lower-tier source and is not in Trezor's public statement, so treat it as unconfirmed, though it would materially raise the credibility of any impersonation attempt built on this data.

No private keys, wallet backups, seed phrases, or device credentials were exposed. Trezor is unambiguous on this point and it is corroborated by every outlet: the hardware itself is not compromised.

The sensitivity here is not in any single field. It is in the join. A verified name plus a verified street address plus a phone number plus proof of a hardware wallet purchase is a qualified target list, and the purchase itself is the qualifier.

Why It Matters

Trezor's public messaging frames the risk as phishing. Its notice warns that "scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor." That is accurate but incomplete, and the gap was noticed immediately.

The Register calls out directly that Trezor "made no mention of the potential for the exposed information to facilitate physical attacks against cryptocurrency holders," and points to a documented pattern of kidnappings and violent robberies targeting wealthy crypto holders and their relatives in France, the US, and elsewhere. CryptoPotato reports the same reaction from customers on X, quoting one reply as "Phishing?? They have physical addresses, you imbeciles" and another describing the exposure as "irl phishing." CoinDesk frames the incident as the first time Trezor customers' shipping addresses have been exposed.

That is the strategic point for defenders. A list linking real names to real home addresses, filtered to people who bought a device whose entire purpose is holding bearer assets, is a wrench-attack targeting package. Unlike a password, an address cannot be rotated. The exposure is permanent for anyone who does not move house.

The second lesson is supply chain scope. Trezor's threat model, product design, and security engineering were not defeated. A vendor two steps removed from the product was. Trezor did more than most here: it contractually imposed a 90-day retention ceiling on its fulfillment partners, and by its own account that policy is what kept the blast radius at five figures rather than years of order history. The policy still did not prevent the breach, and its enforcement is now in question given the update about older orders in the partial-exposure set.

Trezor has also said it is targeting an Anonymous Delivery option for the EU by September 2026, per news.bitcoin.com.

The Attack Technique

Trezor's own disclosure does not explain how ShipMonk was breached. Two OUTLET-tier sources fill that in, with caveats.

SecurityWeek reports that ShipMonk notified its customers that attackers accessed data by exploiting a vulnerability in Metabase, the open-source business intelligence platform, and assesses that the targeted bug is "likely" the SQL injection zero-day Metabase patched the week prior. BleepingComputer's article references the same Metabase zero-day data theft activity and states that its reporters reviewed breach notification emails sent to affected customers. SecurityWeek further reports that the extortion group ShinyHunters claimed responsibility.

Handle this carefully. The Metabase vector is reported by press citing ShipMonk's own customer notifications rather than by a public ShipMonk advisory in these sources, the specific CVE mapping is explicitly hedged as "likely," and the ShinyHunters attribution is an actor claim, not a confirmed finding. Trezor itself has said nothing about the intrusion vector. Directionally, though, this fits a well-established ShinyHunters pattern: mass exploitation of an internet-facing SaaS or BI tool, bulk exfiltration of whatever customer records that tool can reach, then extortion of downstream brands whose data was sitting in it.

What Organizations Should Do

  1. Inventory internet-facing BI and analytics tooling now. Metabase, and platforms like it, sit on top of production databases with broad read access and are frequently excluded from tier-one asset inventories. Patch to current Metabase releases, restrict these consoles to VPN or SSO-gated access, and give them read-only accounts scoped to the minimum necessary tables.
  2. Treat fulfillment and logistics vendors as tier-one data processors. They hold the complete physical-address graph of your customer base. Contractual retention ceilings like Trezor's 90-day policy are the right control, but require evidence: periodic deletion attestations, log exports, and audit rights, not just a clause.
  3. Model physical risk, not just credential risk, in breach comms. If your product implies the customer holds high-value bearer assets, an address leak is a personal safety event. Say so in the notification and give concrete guidance rather than a generic phishing warning.
  4. Pre-position anti-impersonation controls. Publish which channels you will never contact customers through, never ask for a recovery seed under any circumstances, and consider signed or verifiable notification formats. Trezor's own advice applies broadly: treat any message demanding immediate action as suspicious, verify through official channels only, and never enter a wallet backup on a website.
  5. Assume the exposed window will grow. Trezor's stated 90-day boundary already moved for one cohort of customers. Build disclosure language and detection scope for the possibility that vendor-side retention did not match vendor-side reality.
  6. Watch for postal and voice fraud, not only email. With verified name, address, and phone in hand, attackers can send physical letters containing QR codes or fake replacement devices, and place voice calls that pass the usual identity checks. Route customer reports of suspicious mail and calls into the same intake as phishing.

Sources: Crypto wallet maker Trezor confirms 13,000 customers' details expos... | Trezor discloses data breach affecting nearly 14,000 customers | 14,000 Trezor Customers Impacted by Data Breach at ShipMonk - Secur... | Third-party breach exposes shipping addresses of 14,000 Trezor buyers | Trezor Shipping Provider Exposes 13,689 Crypto Customers to Scams | Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardw... | Recent customer data exposed in shipping provider incident | Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Ha...