Trezor Says ShipMonk Breach Exposed 67,000 More US Customers via Metabase Zero-Day, Total Nears 80,700
Trezor Confirms Expanded ShipMonk Breach Affecting 67,000 More US Customers
Trezor has disclosed a second, larger wave of customer data exposure connected to its third-party fulfillment provider, ShipMonk. The company says the total number of affected customers now stands at approximately 80,700, combining a newly disclosed group of 67,000 US customers with a previously reported set of 13,689. Trezor has been clear that this incident is tied to a fulfillment vendor rather than any compromise of its hardware devices or core wallet security.
What Data Was Exposed
Trezor's disclosure states that the exposed data includes names, email addresses, phone numbers, shipping addresses, and order numbers. The affected records reportedly stem from orders placed between November 2019 and August 2021. Trezor has said that no financial credentials, wallet seed phrases, or private keys were involved in the exposure.
How the Breach Happened: A Broken Deletion Promise
Trezor says ShipMonk had previously provided written confirmation that this older order data had been deleted in line with contractual data retention terms. That assurance turned out to be inaccurate, and the retained data was later exposed. Many observers note that this points to a recurring failure mode in third-party data lifecycle management, an issue of vendor accountability and follow-through rather than merely an external hacking event.
The Technical Root Cause: A Critical Metabase Vulnerability
Reporting traces the breach to exploitation of CVE-2026-72898, a SQL injection vulnerability in Metabase rated at the maximum CVSS severity of 10.0. Security firm Holborn has attributed the intrusion to the ShinyHunters extortion group. That attribution comes from a third-party security firm and has not been independently verified by the outlets covering the story, so it should be treated as a reported claim rather than a confirmed fact.
Trezor's Response and What Remains Unconfirmed
Trezor maintains that its own systems and hardware devices were not compromised, framing the exposure as isolated to fulfillment-related customer data. The company has issued guidance warning customers about phishing, impersonation, and social engineering risks that could stem from exposed order history. As of this reporting, ShipMonk itself has not publicly acknowledged or commented on the breach, a silence that has become a recurring concern among affected customers given the lack of transparency from the vendor at the center of the incident.
Why This Matters: Third-Party Risk in the Crypto Industry
This is not Trezor's first vendor-related exposure; the company previously disclosed an incident involving email provider Brevo. Taken together, these episodes illustrate how hardware wallet security, however robust on its own, can be undermined by weaker links in fulfillment and logistics vendors. A recurring theme among industry observers is that vendor data retention audits and deletion verification, rather than contractual promises alone, are what actually determine whether customer data stays protected.
What Affected Customers Should Do
Customers who may be affected are encouraged to stay alert to phishing emails, texts, or calls that reference past Trezor order details. Security guidance consistently emphasizes avoiding links in unsolicited messages and never sharing seed phrases or recovery information, regardless of how legitimate a message may appear. Trezor has also pointed to privacy-focused practices going forward, including anonymous delivery options where available, as a way to reduce future exposure risk.