Home / Blog / Trezor discloses data breach affecting nearly 14,000…
Tech News

Trezor discloses data breach affecting nearly 14,000 customers

I'll pull the BleepingComputer report and the official Trezor disclosure so the paragraphs stay on named facts, not invented figures.The official notice and…

By Dillip Chowdary • Aug 16, 2026 • Source: BleepingComputer

Trezor discloses data breach affecting nearly 14,000 customers

What happened

I'll pull the BleepingComputer report and the official Trezor disclosure so the paragraphs stay on named facts, not invented figures.The official notice and the BleepingComputer write-up will pin down the exposure split, the order window, and what Trezor says was not taken.Trezor disclosed on Thursday, August 13, 2026 that a breach at ShipMonk, the shipping and logistics provider that stores its products and ships orders, exposed personal data for nearly 14,000 customers. ShipMonk informed Trezor on Monday, August 10 of unauthorized access to systems holding customer order data. Trezor split the impact into two cohorts: 11,742 customers with full exposure of name, email, phone number, and shipping address, and 1,947 customers with partial exposure of name, city, and email, for a total of approximately 13,689 people. The affected orders went to the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal and were received between May 10 and August 8, 2026. Trezor said its own systems were not compromised, that operations and services continue as normal, and that Trezor devices, private keys, and wallet backups were not part of the incident. Affected customers were contacted separately by email from the company’s security address; anyone who did not receive that message is outside the disclosed set.

The blast radius is a fulfillment-data problem, not a wallet-firmware problem. ShipMonk holds what a parcel carrier needs to deliver a physical device: name, email, order number, phone number, and shipping address. Trezor requires fulfillment partners to delete or anonymize that data 90 days after delivery, and it said that policy is why older orders were not supposed to still be in ShipMonk systems. In notification emails reviewed by BleepingComputer, ShipMonk told customers that on August 6, 2026 Metabase informed it that an unauthorized party had exploited a vulnerability in Metabase software to access data related to ShipMonk’s account and its customers. BleepingComputer tied that path to a critical SQL injection zero-day in Metabase that let attackers take administrator access on customer instances and steal data. Metabase later patched the vulnerability and invalidated active sessions; ShipMonk said it also opened a technical investigation with outside experts. Trezor itself did not describe how ShipMonk was breached.

The technical detail

Trezor discloses data breach affecting nearly 14,000 customers
Illustration · Pexels

For engineers who ship hardware, or who put customer PII next to a BI tool, the architecture lesson is concrete. A hardware wallet is designed so private keys never leave the device, which is why Trezor can truthfully say the device and the seed are still safe. The same product still has to move through a third-party warehouse, a label printer, and a carrier, and those hops require a name, a phone, and a street address. Putting that warehouse data behind Metabase, a third-party analytics platform, added another query surface that was not on Trezor’s own perimeter. The 90-day retention window is the only control Trezor cited that actually bounded the count. That is a useful design choice to copy: treat fulfillment PII as a time-boxed secret, contract the same deletion deadline with the 3PL, and do not assume an analytics layer on top of that store is out of scope for threat modeling.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

Why it matters for builders

The same Metabase campaign already hit other companies. BleepingComputer previously reported that laptop maker Framework and form builder Tally also notified customers after their Metabase instances were hijacked. BleepingComputer has since learned that ShipMonk received extortion emails from the ShinyHunters extortion gang. Hardware shipping is not unique to crypto either: Valve notified Steam hardware customers in Europe that hackers stole their data after compromising CEVA Logistics, Valve’s shipping partner. Inside the wallet market the incident is more pointed because a shipping address plus a recent Trezor order is a high-signal hint that a household holds a cold-storage device. Trezor called this the first time since it was founded in 2013 that a breach exposed customer phone numbers and shipping addresses.

Market and competitive context

The immediate watch list is phishing that uses real order facts, not a firmware update. Trezor warned that scammers can send fake emails, make fake phone calls, send fraudulent letters, or impersonate banks, crypto exchanges, or Trezor itself, and that affected customers should treat any message that demands immediate action or personal information as hostile. The standing rule is unchanged: never enter a wallet backup on a website and never share it with anyone. Trezor also said it is building an Anonymous Delivery option with a dedicated checkout, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery, aimed at the EU by September 2026 and the United States by the end of 2026. Until that ships, the company’s own advice is an anonymous email at checkout, crypto or a disposable card for payment, and a P.O. Box where that is workable. Separately, Trezor updated its notice to say the 1,947 partial-exposure records may include older orders than the 90-day window, and that it is still verifying that timeframe with ShipMonk.

What to watch next

Two open questions sit on top of prior art. First, Trezor has not said how long the Metabase instance was exposed before August 6, or whether the 11,742 full-address records will be used for physical targeting as well as inbox phishing. Second, if the 1,947 partial records do include older orders, the 90-day deletion contract did not hold for every field, which is the kind of partner-compliance gap that only shows up after an incident. This is also not Trezor’s first third-party leak. In January 2024 the company disclosed that attackers had accessed its third-party support ticketing portal and that 66,000 users who had interacted with Trezor Support since December 2021 may have had names, usernames, and email addresses exposed. After that breach, Trezor confirmed the attackers used the stolen information in phishing campaigns that tried to trick recipients into revealing the 24-word recovery seeds issued when a Trezor wallet is set up. The ShipMonk set is smaller but richer, because a phone number and a street address let the same playbook move from email to voice and mail. The next facts that matter are ShipMonk’s completed investigation, whether ShinyHunters publishes or auctions the Trezor slice, and whether Trezor confirms that the 1,947 older-order records are real.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →