On September 2, Trezor learned that a breach at its fulfillment partner ShipMonk was larger than initially reported. Another 67,000 U.S. customers had their personal data exposed—names, email addresses, phone numbers, shipping addresses, and order numbers—bringing the total to roughly 80,689. The affected orders span November 2019 to August 2021. Trezor’s devices were not compromised. The attack went through ShipMonk’s systems, specifically a Metabase instance that ShipMonk ran on the public internet.
The entry point was CVE-2026-72898, an unauthenticated SQL injection in Metabase’s password reset endpoint carrying a CVSS score of 10.0. Metabase published the advisory on August 6. By August 11, CISA had added the vulnerability to its Known Exploited Vulnerabilities catalog with confirmed ransomware use.
The mechanics are straightforward. The /api/session/reset_password endpoint allowed unauthenticated SQL injection into Metabase’s application database, granting administrator access. From there, attackers could change application configuration, steal stored credentials for connected databases, and export data. Horizon3 estimated roughly 4,309 of 11,000 internet-exposed Metabase instances were likely vulnerable. ShipMonk’s was one of them.
Trezor had a contract requiring ShipMonk to delete customer data after 90 days. The company repeatedly requested and received written confirmation that deletion had occurred. It had not. As Trezor stated in its official disclosure: “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”
The breach follows a pattern this beat has tracked across multiple infrastructure layers. When management tools or business intelligence platforms sit on the public internet without authentication, they become pivot points—regardless of how secure the primary product is. PaperCut’s print management server. N-able’s MSP console. Microsoft’s self-service password reset. Cisco’s management plane. In each case, the exposure was not at the product level but at the operational tooling level. Trezor extends that pattern into crypto supply chains. The wallet was never the target. The warehouse’s analytics stack was.
The blast radius of CVE-2026-72898 reached well beyond ShipMonk. Framework, Anaconda, and n8n—all Metabase Cloud tenants—reported unauthorized access to customer data during the pre-patch window. A ShinyHunters leak-site listing labeled “Metabase” appeared with approximately 7 gigabytes of related data, though the scope remains unconfirmed. Halborn, the enterprise blockchain security firm, attributed the Trezor breach to ShinyHunters, describing it as “a supply chain attack beginning with a zero-day vulnerability” where “the attackers were able to exploit several of its customers, stealing sensitive data and extorting the organization.” That attribution rests on pattern analysis and third-party reporting, not direct technical evidence. ShipMonk has not publicly acknowledged the incident.
The exposed data—phone numbers, shipping addresses, order history—provides immediate material for targeted phishing against crypto hardware buyers. Trezor warned customers about precisely this risk. For security practitioners, the structural question is whether vendor risk management programs can enforce the technical controls that contractual clauses clearly cannot. Written assurances about data deletion did not prevent the data from persisting on an internet-facing BI tool with an unauthenticated critical vulnerability. The gap between contractual expectation and technical reality is where attackers operate.
