Trezor Data Breach Exposes 13,689 Customer Addresses

  • Trezor says 11,742 customers had full data exposed and 1,947 had partial data exposed.
  • The breach came from shipping provider ShipMonk, not Trezor's own systems.
  • Attackers exploited a Metabase SQL injection zero-day that also hit Framework and Tally.
Trezor Data Breach Exposes 13,689 Customer Addresses
Image Source

Hardware wallet manufacturer Trezor has disclosed a data breach affecting close to 14,000 customers after ShipMonk, the company’s shipping and logistics provider, was hacked.

What was exposed

Attackers gained access to customer order data, including full names, shipping addresses, email addresses, and phone numbers.

In a blog post published Thursday, Trezor said the incident hit customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10 and August 8, 2026.

The company wrote:

“On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data. The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email).”

Phishing risk for wallet owners

Trezor stressed that its own systems were untouched and that operations, services, and devices remain secure, but warned that leaked shipping data makes affected buyers prime targets for social engineering.

The company noted:

“Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor.”

Metabase zero-day at the root

In notification emails to customers, ShipMonk said the attackers exploited a vulnerability in the third-party analytics platform Metabase, which has since been patched with all active sessions invalidated.

Metabase previously confirmed that a critical SQL injection zero-day was used to gain administrator access to customer instances, with laptop maker Framework and form builder Tally also caught up in the same campaign.

This is not Trezor’s first incident of this kind.

In January 2024, a breach of its third-party support ticketing portal exposed data on 66,000 users, and attackers later used that information in phishing attempts aimed at tricking victims into handing over their 24-word recovery seeds.

Original Article