Published Security3 min read
Trezor's systems held. Its shipping list did not.
A Metabase zero-day at fulfillment provider ShipMonk exposed 11,742 Trezor customers in full, including home shipping addresses and phone numbers. The devices are fine. The list is the problem.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked.
- During the incident, the attackers gained access to customers' order data, including their full names, shipping addresses, email addresses, and phone numbers.
- In a Thursday blog post, Trezor said the breach affects customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026.
- Trezor said: "The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email)."
- Trezor said its operations and services were not impacted by the breach, that its systems were not compromised, and that all Trezor devices are secure.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Trezor told customers in a Thursday blog post that order records for nearly 14,000 people were taken from ShipMonk, its shipping and logistics provider, and stressed that its own systems were not compromised and that its devices remain secure [1][3][5]. Both statements can be true without either being reassuring: the data that leaked pairs full names with home shipping addresses and phone numbers, and that is the part with resale value [2][4].
The split matters. Trezor puts 11,742 customers in the full exposure bucket, meaning name, email, phone number and shipping address, and 1,947 in a partial bucket holding name, city and email [4]. That is 13,689 people in total, roughly 86 percent of them fully populated [1][2]. The affected orders were delivered between May 10 and August 8, 2026, a window of about 90 days, to customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal [3][3].
What separates this from the usual name-and-email spill is the street address. Trezor's own notice lists the expected uses: fake emails, fake phone calls, fraudulent letters, and impersonation of banks, crypto exchanges or Trezor itself [6]. The letters are the item to take seriously, because a piece of postal mail bearing a correct name and delivery address carries an authority that a cold email does not, and because this vendor's customers have been worked before. After Trezor's January 2024 breach of a third-party support ticketing portal, which exposed names, usernames and email addresses for 66,000 users who had contacted support since December 2021, the company confirmed that attackers used the stolen data to phish for users' 24-word recovery seeds [13][14]. That campaign had to guess who its targets were. This one knows where the box was delivered.
The failure sits one layer further out than ShipMonk. Trezor did not say how its provider was breached [8]. According to breach notification emails ShipMonk sent to customers and reviewed by BleepingComputer, the entry point was a vulnerability in the third-party analytics platform Metabase, and ShipMonk says Metabase informed it on August 6, 2026 that an unauthorized party had exploited that flaw to reach data tied to its account and its customers [8][9]. Metabase has said the attacks used a critical SQL injection zero-day to obtain administrator access to customer instances and carry out data theft [11]. ShipMonk says, on the vendor's representations, that the vulnerability is patched and all active sessions invalidated, and that it engaged outside IT experts to investigate [10]. ShipMonk notified Trezor on August 10, four days after being notified itself [7][4].
Trezor is not the only downstream casualty of that instance-level compromise: laptop maker Framework and form builder Tally have also notified customers after their Metabase instances were hijacked [12]. Fulfillment keeps producing this shape of incident. Valve notified European Steam hardware buyers on Monday that their data was stolen when its shipping partner CEVA Logistics was hacked [15].
Three things to watch. First, reports of physical mail and voice calls aimed at the 11,742-record cohort, since that is what the address and phone fields buy an attacker [4]. Second, how many more ShipMonk merchants disclose, and how many more Metabase instances turn out to have been reachable [11][12]. Third, what Trezor says about the retention terms it sets for fulfillment partners, given that a 90-day order window was sitting in a third party's analytics stack [3]. A Trezor spokesperson was not immediately available for comment when contacted by BleepingComputer [16].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked.
- [2]
During the incident, the attackers gained access to customers' order data, including their full names, shipping addresses, email addresses, and phone numbers.
- [3]
In a Thursday blog post, Trezor said the breach affects customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026.
- [4]
Trezor said: "The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email)."
- [5]
Trezor said its operations and services were not impacted by the breach, that its systems were not compromised, and that all Trezor devices are secure.
- [6]
Trezor warned that affected customers may see an increase in phishing attempts and said: "Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor."
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comSergiu GatlanAug 13Trezor discloses data breach affecting nearly 14,000 customers
Additional citations
- Trezor, via BleepingComputer
- Trezor blog post
- Trezor
- ShipMonk breach notification emails reviewed by BleepingComputer
- ShipMonk
- Metabase, as previously reported by BleepingComputer



