>samit_hota
Back to security news

Security News · SN-2026-406

HIGHMITIGATED

Trezor Data Breach Exposes Customer Details via ShipMonk Hack

Affected: Trezor · ShipMonk · Metabase · Framework · Tally

Samit Hota·
#news#vulnerability-disclosure#trezor

Customer shipping details for thousands of cryptocurrency hardware wallet owners have been exposed following a third-party supply chain compromise. The latest Trezor data breach stems from an intrusion at shipping and logistics provider ShipMonk, which was compromised after threat actors exploited a zero-day vulnerability in the Metabase business intelligence platform. While Trezor’s core infrastructure and crypto wallet devices remain secure, the incident has leaked sensitive physical and digital contact information for nearly 14,000 users across multiple countries.

Supply Chain Compromise Exposes Wallet Buyers

Trezor received notice of the breach from ShipMonk on August 10, 2026, after the logistics provider detected unauthorized access to customer order databases. The breach impacts individuals who placed orders between May 10 and August 8, 2026, across seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.

According to breach notification records, the stolen data is categorized by two distinct exposure levels:

  • Full Exposure (11,742 customers): Full name, email address, phone number, and physical shipping address.
  • Partial Exposure (1,947 customers): Full name, city, and email address.

Trezor confirmed that its internal networks, production infrastructure, and wallet hardware were unaffected by the incident. However, because hardware wallet owners represent high-value targets in the cryptocurrency ecosystem, the leak of physical addresses alongside personal contact details presents severe downstream security risks for affected buyers.

Root Cause: Zero-Day SQL Injection in Metabase

The initial access vector responsible for the supply chain breach originated not at ShipMonk itself, but through its deployment of Metabase, a widely used open-source business analytics and reporting tool. On August 6, 2026, Metabase alerted customers that an unauthorized third party had leveraged a critical zero-day SQL injection (SQLi) vulnerability to breach customer-hosted instances.

SQL injection vulnerabilities occur when an application fails to properly sanitize user-supplied input before incorporating it into database queries. In this case, attackers exploited the SQLi flaw to gain administrative privileges over the Metabase instance. Business intelligence platforms like Metabase are particularly high-value targets because they are designed to aggregate data from core transactional databases, analytics pipelines, and customer management systems. Once an attacker achieves administrative access on such an instance, they can execute arbitrary database queries, bypass access controls, hijack active sessions, and dump entire underlying data stores.

After discovering the zero-day exploitation, Metabase released a patch and forcibly invalidated all active user sessions across customer deployments. However, by the time mitigation measures were deployed, threat actors had already exfiltrated customer order records from ShipMonk and several other organizations using compromised Metabase installations, including laptop manufacturer Framework and online form builder Tally.

Threat Actor Spotlight: ShinyHunters

The extortion gang ShinyHunters has been identified as the threat actor behind the ShipMonk intrusion, having dispatched extortion emails directly to the logistics provider following the data exfiltration.

ShinyHunters is a well-established cybercrime group active since at least 2020, infamous for executing large-scale data theft and ransom operations. The group typically targets cloud-hosted databases, third-party SaaS platforms, and enterprise data analytics software. Their operational model relies heavily on exfiltrating vast quantities of personally identifiable information (PII) and corporate records, followed by double-extortion demands. If a victim organization refuses to pay, ShinyHunters typically publishes or sells the stolen databases on illicit cybercrime forums such as BreachForums, exposing victims to secondary attacks from lower-tier cybercriminals.

Phishing and Physical Security Risks

Data breaches involving hardware wallet manufacturers carry risks far beyond standard corporate PII leaks. When threat actors associate a real-world name and physical home address with cryptocurrency ownership, affected users face heightened physical and digital threat vectors.

The primary immediate threat is targeted spear-phishing. Attackers routinely leverage stolen order histories to construct convincing, highly targeted lure scenarios. These often take the form of:

  • Fake security advisories claiming the user’s hardware wallet has been compromised and requiring an immediate firmware update.
  • Fraudulent replacement offers urging the user to order a new device or claim a recall.
  • Direct phone calls, text messages, or physical mail impersonating Trezor, financial institutions, or crypto exchanges.

The primary objective of these campaigns is almost always seed phrase harvesting. Scammers attempt to trick the victim into typing their 24-word recovery seed into a malicious website or phishing app. Anyone who gains access to a wallet’s seed phrase gains full, irreversible control over the associated cryptocurrency funds.

This risk profile is demonstrated by past security incidents. When Trezor experienced a breach in January 2024 involving a third-party support ticketing system—exposing 66,000 user contacts—attackers immediately launched automated phishing campaigns designed to steal seed phrases. Furthermore, the correlation of physical shipping addresses with cryptocurrency ownership introduces potential real-world physical extortion risks.

This incident also highlights a broader pattern of threat actors targeting e-commerce supply chains and third-party logistics (3PL) partners to steal target data. Valve recently issued similar breach notifications to European Steam hardware buyers after logistics partner CEVA Logistics was breached.

Organization administrators using Metabase must verify immediately that their installations are updated to the latest vendor-supplied patch release and confirm that all historical session tokens have been revoked. Organizations should audit database privileges assigned to business intelligence tools, ensuring that analytics software operates under strict least-privilege constraints to limit data exposure in the event of an application-level compromise.

For affected Trezor customers, immediate protective steps include:

  • Never reveal your 24-word recovery seed. Trezor will never ask for a seed phrase via email, phone, physical mail, or website form. Recovery seeds should only ever be entered directly into the physical Trezor device screen during disaster recovery.
  • Treat unexpected communications as hostile. Assume any incoming calls, text messages, or emails regarding wallet security, order status, or account verification are unauthorized phishing attempts.
  • Verify domain legitimacy. If you receive security notices, navigate directly to official vendor sites via manual bookmarks rather than clicking links inside emails or text messages.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call