What ShipMonk exposed, and when

On August 13, 2026, Trezor told customers that ShipMonk, the third-party warehouse and shipping provider it uses to fulfil hardware wallet orders, had informed it three days earlier, on Monday August 10, of unauthorized access to systems holding customer data. The exposure covers orders placed between May 10 and August 8, 2026: 11,742 customers had their full name, email address, phone number and shipping address exposed, and a further 1,947 had a narrower set, name, city and email, taken.

The affected customers span at least seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor said it notified every affected customer directly by email and that anyone who did not receive a notice was not part of the exposure.

The same flaw, a different kind of victim

ShipMonk told Trezor and its own customers that the intrusion traced back to a SQL injection vulnerability in Metabase, the business-intelligence platform many companies plug into their operational data to run internal dashboards. That is notable because a separate wave of breaches earlier this month, at Framework, Tally and LexisNexis, traced to the same underlying Metabase flaw, with attackers using an unauthenticated password-reset endpoint to gain administrator access to each company's instance in turn.

ShipMonk also confirmed it received extortion emails from ShinyHunters, a group with a long track record of following up SaaS and BI-platform intrusions with direct payment demands to the breached company rather than, or in addition to, quietly reselling the data. Trezor was explicit that its own hardware, firmware and account systems were never touched: ShipMonk only ever held the fulfilment data Trezor gave it to get a package to a doorstep, and Trezor called this the first breach since its 2013 founding to expose customer phone numbers and shipping addresses.

Why a shipping address here is worth more than a password

Most vendor breaches of this shape get filed under the same heading: expect more convincing phishing email. That framing understates what is different about a shipping list tied to a hardware crypto wallet order. Every name on it is a verified, physical-address-confirmed owner of self-custody crypto hardware, a combination that criminals researching in-person targets cannot usually get from a stolen SaaS customer list, a leaked forum dump, or on-chain analysis alone.

Chainalysis, the blockchain analytics firm that tracks crypto-related crime, has documented an escalating run of violent, in-person attacks on crypto holders, so-called wrench attacks, kidnappings, home invasions and coercion carried out specifically because the victim was known or suspected to hold recoverable digital assets. Chainalysis figures put the value stolen in these physical attacks at more than 30 million dollars in the first half of 2026 alone, already on pace to exceed the roughly 58 million dollars tracked for the whole of 2025. A list that hands an attacker a name, a home address and hard proof of hardware-wallet ownership is precisely the input that trend runs on.

Where the standard playbook falls short

The instinct after a breach like this is to reach for the anti-phishing checklist: watch for fake delivery texts, do not click unexpected links, verify any request to confirm an address before replying. Those steps matter, but they answer the wrong threat model here. Phishing targets a screen. A wrench attack targets a front door, and no amount of email hygiene changes who now has a customer's real address on file alongside proof they own a hardware wallet.

The more useful response for anyone on Trezor's affected list is physical, not digital: treat unsolicited in-person contact, callers claiming to be couriers, technicians or officials, with the same suspicion as a phishing email, avoid publicly confirming crypto holdings tied to a home address, and, where the exposure includes a full address, consider it a signal to review physical security at that location rather than only rotating passwords that were never at risk. For any business that ships a product whose ownership alone marks a customer as wealthy, whether crypto hardware, jewelry, or high-value electronics, that same logic applies: a fulfilment vendor's data is not just a privacy asset, it is a target list waiting to be built, and it deserves a physical-risk review alongside the usual vendor-security audit.