Markets
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
Business

A Metabase Bug at Trezor's Shipping Partner Exposed 13,689 Buyers

ShipMonk lost 90 days of order data to attackers who exploited a flaw in the third-party analytics tool Metabase, handing out full names, phone numbers and shipping addresses for anyone waiting on a hardware wallet.

By Tom Chen··3 min read
A Metabase Bug at Trezor's Shipping Partner Exposed 13,689 Buyers

Key Points

  • ShipMonk lost 90 days of order data to attackers who exploited a flaw in the third-party analytics tool Metabase, handing out full names, phone numbers and shipping addresses for anyone waiting on a hardware wallet.

Trezor said on Wednesday that a data breach at ShipMonk, the logistics firm that stores and dispatches its hardware wallets in seven markets, exposed the personal details of 13,689 customers. ShipMonk notified Trezor on Monday, 10 August. The attackers had exploited a vulnerability in Metabase, the third-party analytics platform ShipMonk uses to query its order data.

The breakdown, published in Trezor's disclosure blog: 11,742 customers had full order records exposed — name, email, phone number and shipping address — and 1,947 had a smaller set including name, city and email. The affected orders were placed between 10 May and 8 August 2026 by buyers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor is emailing everyone affected from a dedicated address; customers who do not receive that email are not on the list.

The scale is smaller than it might have been. Trezor requires its shipping partners to delete or anonymise order data 90 days after a parcel is delivered, and that policy caught almost all of the older records before they could be taken. The company said it is now checking with ShipMonk whether the 1,947-customer partial-exposure cohort somehow contains buyers whose orders should have been outside the retention window.

Advertisement

728×90

Trezor's own systems were not compromised. The Trezor devices sitting in customer drawers remain cryptographically secure; nothing about the breach touches private keys or wallet backups. What it does hand attackers is a phishing kit for one of the most valuable targets in consumer software. If someone has a fresh Trezor and a leaked home address, a physical letter that appears to come from SatoshiLabs asking the recipient to "validate" a seed phrase is not a hard piece of theatre to stage.

That is not hypothetical. Ledger's 2020 shipping-database leak produced years of increasingly polished phishing campaigns, including at least one wave of physical letters mailed to victims. Hardware wallet users are already the most heavily targeted phishing cohort in crypto — the calculation for attackers is straightforward, because the payoff per successful seed extraction is measured in five or six figures. A verified list of recent buyers is worth more per name than almost any other leaked dataset.

Metabase is an open-source business-intelligence tool used by a large share of e-commerce operators. A high-severity remote-code-execution flaw disclosed in 2023, CVE-2023-38646, allowed attackers to run arbitrary code on unpatched instances without authentication. Metabase deployments have been targeted repeatedly since. ShipMonk has not published a technical writeup and has not said which specific flaw was exploited, but the company has told Trezor that the affected systems are now secured.

This is the first customer data leak in Trezor's 12-year history to expose phone numbers and shipping addresses. The company said as much in its disclosure, and the tone of the post is closer to contrition than corporate defence. Trezor is offering an anonymous-delivery option as the structural fix: a dedicated checkout, locker pickup, neutral packaging, and automatic deletion of shipping identifiers after handover. That option is scheduled for the EU in September and the US by end-2026.

The workaround assumes customers were ever going to accept the trade-off. Anyone ordering a hardware wallet is doing so because they do not want a third party to hold their keys. Handing full home addresses to a fulfilment vendor is the mirror image of that intent, and the industry has now had two large-scale reminders in five years that shipping data is a live attack surface. The $130 million Coldcard exploit still working through its third wave is a firmware failure, not a shipping one, but it belongs to the same conversation about how much operational risk actually sits between a self-custody buyer and the security promise on the box.

Affected Trezor customers should assume the phishing wave is already underway. The company's practical advice is unchanged: never type a wallet backup into any web form, ignore any prompt to "verify" a seed by phone or email, and treat any physical letter referencing a recent Trezor order as hostile until proven otherwise.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.