Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Business

A Metabase Bug at Trezor's Shipping Partner Exposed 13,689 Buyers

ShipMonk lost 90 days of order data to attackers who exploited a flaw in the third-party analytics tool Metabase, handing out full names, phone numbers and shipping addresses for anyone waiting on a hardware wallet.

By Tom Chen··3 min read
A Metabase Bug at Trezor's Shipping Partner Exposed 13,689 Buyers

Key Points

  • ShipMonk lost 90 days of order data to attackers who exploited a flaw in the third-party analytics tool Metabase, handing out full names, phone numbers and shipping addresses for anyone waiting on a hardware wallet.

Trezor said on Wednesday that a data breach at ShipMonk, the logistics firm that stores and dispatches its hardware wallets in seven markets, exposed the personal details of 13,689 customers. ShipMonk notified Trezor on Monday, 10 August. The attackers had exploited a vulnerability in Metabase, the third-party analytics platform ShipMonk uses to query its order data.

The breakdown, published in Trezor's disclosure blog: 11,742 customers had full order records exposed — name, email, phone number and shipping address — and 1,947 had a smaller set including name, city and email. The affected orders were placed between 10 May and 8 August 2026 by buyers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor is emailing everyone affected from a dedicated address; customers who do not receive that email are not on the list.

The scale is smaller than it might have been. Trezor requires its shipping partners to delete or anonymise order data 90 days after a parcel is delivered, and that policy caught almost all of the older records before they could be taken. The company said it is now checking with ShipMonk whether the 1,947-customer partial-exposure cohort somehow contains buyers whose orders should have been outside the retention window.

Advertisement

728×90

Trezor's own systems were not compromised. The Trezor devices sitting in customer drawers remain cryptographically secure; nothing about the breach touches private keys or wallet backups. What it does hand attackers is a phishing kit for one of the most valuable targets in consumer software. If someone has a fresh Trezor and a leaked home address, a physical letter that appears to come from SatoshiLabs asking the recipient to "validate" a seed phrase is not a hard piece of theatre to stage.

That is not hypothetical. Ledger's 2020 shipping-database leak produced years of increasingly polished phishing campaigns, including at least one wave of physical letters mailed to victims. Hardware wallet users are already the most heavily targeted phishing cohort in crypto — the calculation for attackers is straightforward, because the payoff per successful seed extraction is measured in five or six figures. A verified list of recent buyers is worth more per name than almost any other leaked dataset.

Metabase is an open-source business-intelligence tool used by a large share of e-commerce operators. A high-severity remote-code-execution flaw disclosed in 2023, CVE-2023-38646, allowed attackers to run arbitrary code on unpatched instances without authentication. Metabase deployments have been targeted repeatedly since. ShipMonk has not published a technical writeup and has not said which specific flaw was exploited, but the company has told Trezor that the affected systems are now secured.

This is the first customer data leak in Trezor's 12-year history to expose phone numbers and shipping addresses. The company said as much in its disclosure, and the tone of the post is closer to contrition than corporate defence. Trezor is offering an anonymous-delivery option as the structural fix: a dedicated checkout, locker pickup, neutral packaging, and automatic deletion of shipping identifiers after handover. That option is scheduled for the EU in September and the US by end-2026.

The workaround assumes customers were ever going to accept the trade-off. Anyone ordering a hardware wallet is doing so because they do not want a third party to hold their keys. Handing full home addresses to a fulfilment vendor is the mirror image of that intent, and the industry has now had two large-scale reminders in five years that shipping data is a live attack surface. The $130 million Coldcard exploit still working through its third wave is a firmware failure, not a shipping one, but it belongs to the same conversation about how much operational risk actually sits between a self-custody buyer and the security promise on the box.

Affected Trezor customers should assume the phishing wave is already underway. The company's practical advice is unchanged: never type a wallet backup into any web form, ignore any prompt to "verify" a seed by phone or email, and treat any physical letter referencing a recent Trezor order as hostile until proven otherwise.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Cboe's 25-Year S&P 500 Options Deal Mentions Tokenized Contracts
Business

The extension gives Cboe the exclusive license to list S&P 500 index options through 2051, a franchise the companies say traded 970.6 million contracts last year. A single permissive sentence adds that the two may also pursue new products like tokenized options, with no product, venue, timetable or filing attached.

·MiningPool Staff
Strategy Put Daily Preferred Dividends to a Shareholder Vote
Business

Total dividends would not change, but STRC's record dates would go from 24 a year to 365 and the other three series from four to 365. Proposal 1 needs a majority of all outstanding common voting power, and the proxy puts Michael Saylor's share of it at 32.9%.

·MiningPool Staff
Kelp's Developer Is Suing LayerZero Over Advice It Says It Followed
Business

Evercrest Technologies filed in the Supreme Court of British Columbia, alleging LayerZero approved its single-verifier bridge configuration in writing and warned another integrator about the same risk without warning Kelp. The claim adds a defamation count over LayerZero's post-exploit statements and seeks Evercrest's own losses rather than the full $292 million.

·MiningPool Staff
NYSE's Tokenized Stock Venue Has a Distributor Before It Has Approval
Business

Blockchain.com signed a memorandum of understanding to route its users to NYSE's planned digital alternative trading system, a venue that has not opened and still needs regulatory clearance. The companies disclosed no financial terms and no launch date, and the market data leg of the deal is the part that can start now.

·MiningPool Staff
Bitdeer Mined 1,310 Bitcoin in August and Ended the Month With 61
Business

The miner's self-mining hashrate rose to 79.9 EH/s and production was up about 249 percent from a year earlier, but its bitcoin balance ended the month at 61 coins, against 257 a month earlier and 1,934 a year ago. The company's own footnote says the figure counts coins pledged as collateral, which rules out one explanation for the drop.

·MiningPool Staff
Celsius's Estate Wants 6,360 Bitcoin Back From a Closing BitMEX
Business

Blockchain Recovery Investment Consortium filed in the Southern District of New York on September 12, eleven days before BitMEX stops trading, over positions liquidated on March 12 and 13, 2020. The complaint alleges the exchange controlled both the liquidation engine and the insurance fund that took the positions over.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.