Published Invest3 min read
Trezor's Threat Model Ended at the Warehouse Door
A Metabase flaw at fulfilment vendor ShipMonk exposed names, emails, phone numbers and home addresses for 11,742 Trezor buyers. The seed phrases are fine. The delivery manifest was the asset.
Context for builders, not their beat.See today for builders

What happened
- A breach at ShipMonk, Trezor's shipping provider, exposed the names and contact details of about 13,689 customers.
- Trezor said 11,742 people had their names, email addresses, phone numbers and shipping addresses taken.
- Another 1,947 people had only their names, cities and email addresses taken.
- Orders shipped between May 10 and August 8 were affected.
- Trezor said it became aware of the breach when ShipMonk shared the information on Monday, August 10.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
Attackers who exploited a flaw in an analytics tool used by ShipMonk, the fulfilment provider that ships Trezor hardware wallets, walked away with names, email addresses, phone numbers and shipping addresses for 11,742 buyers, part of 13,689 customers affected in total across seven countries [1][2][7]. Trezor says its own infrastructure was untouched and wallets remain secure [6], which is true and beside the point: the compromised record is a list of addresses where a device holding bearer assets was recently delivered.
The remaining 1,947 people lost only names, cities and email addresses [3]. That means roughly 86 percent of those affected had a full physical address exposed [1]. Orders shipped between May 10 and August 8 were in scope [4], a window of about 91 days [2] that maps almost exactly onto ShipMonk's policy of deleting or anonymising order records three months after delivery [8]. The retention schedule, not the intrusion, defined the blast radius. Customers who bought through Amazon moved through a different fulfilment channel and were not affected [9].
Trezor learned of the incident when ShipMonk passed on the information on Monday, August 10 [5]. ShipMonk attributed the breach to a vulnerability in Metabase, the third-party analytics platform it uses, which Metabase itself disclosed on August 6 [12]. The bug was a critical SQL injection zero-day granting administrator access, and the same campaign hit laptop maker Framework and form builder Tally [13]. Trezor says it has no evidence the records have been published, sold or used in a scam, while ShipMonk has been receiving extortion emails from the ShinyHunters group [14].
This is smaller than Trezor's previous exposures. A third-party support portal breach in January 2024 affected 66,000 users, and a separate 2022 incident more than 106,000 [11]; 13,689 is about a fifth of the 2024 figure [3]. But Trezor says this is the first of its incidents to expose customer phone numbers and shipping addresses [10], and that changes what the data is worth. Affected buyers face heightened phishing risk by email, phone and post, plus the possibility of physical targeting, which French users have already experienced [18].
The precedent is not hypothetical. Ledger's 2020 breach spilled data on hundreds of thousands of users, and Cryptopolitan reports scammers were still mailing Ledger owners fake "Quantum Resistance Security Update" letters carrying malicious QR codes as recently as May 2026 [15]. Chainalysis reported more than $30 million taken in violent crypto attacks in the first half of 2026, on pace to exceed 2025's full-year $58 million [16]; doubled, the half-year figure annualises to roughly $60 million [4]. Customer lists with addresses are an input to that number.
Trezor has notified affected customers by email and says it will offer a more private shipping option using lockers, neutral packaging and automatic deletion of address data after delivery, targeting the EU by September and the United States by year end [17]. That is the correct fix, and it is an admission that the previous arrangement stored data it did not need to keep.
Watch whether the September EU date holds, and whether any vendor in this chain shortens retention below three months rather than adding packaging changes on top of the same database.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A breach at ShipMonk, Trezor's shipping provider, exposed the names and contact details of about 13,689 customers.
- [2]
Trezor said 11,742 people had their names, email addresses, phone numbers and shipping addresses taken.
- [3]
Another 1,947 people had only their names, cities and email addresses taken.
- [5]
Trezor said it became aware of the breach when ShipMonk shared the information on Monday, August 10.
ReportedView cited source - [6]
Trezor said its own infrastructure was untouched, its systems and devices were not compromised, and user wallets remain secure.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cryptopolitan.comHannah CollymoreAug 13Shipping partner breach exposes data of 14,000 Trezor customers
Additional citations
- Cryptopolitan, citing Trezor
- Trezor via Cryptopolitan
- Trezor
- ShipMonk
- Cryptopolitan
- Chainalysis via Cryptopolitan


