Trezor Supply Chain Breach: 80,000+ Customers' Data Exposed

- Over 80,000 Trezor customers had personal data exposed through a breach at logistics provider ShipMonk.
- The leak includes names, emails, phone numbers, and shipping addresses, though hardware wallet security remains intact.
- Attackers exploited a critical SQL injection zero-day vulnerability (CVE-2026-72898) in the Metabase platform.
- The ShinyHunters extortion gang is suspected of being behind the attack, raising risks of targeted social engineering.
The security of a hardware wallet is often viewed as an absolute, a cryptographic fortress that protects digital assets from the volatility of the internet. However, the recent data breach involving Trezor serves as a stark reminder that the weakest link in the security chain is rarely the encryption itself, but the operational infrastructure surrounding the product. In a cascading series of disclosures, the hardware wallet manufacturer has revealed that tens of thousands of its customers have had their personal information exposed through a third-party shipping partner, ShipMonk.
The expanding scope of the ShipMonk leak
What began as a limited disclosure has evolved into a significant privacy failure. Initially, Trezor reported that 13,689 customers across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal were affected. This first wave primarily concerned orders delivered between May 10 and August 8, 2026. However, a subsequent update on September 5, 2026, revealed a much deeper problem: an additional 67,000 U.S. customers were impacted.
The data exposed in this second, larger wave spans a much wider timeframe, covering orders placed between November 2019 and August 2021. The leaked information is comprehensive, including customer names, email addresses, phone numbers, shipping addresses, and order numbers. While Trezor emphasizes that the security of the hardware wallets, private keys, and seed phrases remains uncompromised, the exposure of physical addresses creates a different, more tangible set of risks.
A failure of data deletion promises
The most contentious aspect of this breach is not the hack itself, but the persistence of the data. Trezor operates under a strict 90-day data storage policy, designed to cover the lifecycle of an order—including delivery, returns, and replacements—after which customer data is supposed to be deleted or anonymized. The company stated that this window is the shortest possible timeframe that ensures operational efficiency without retaining unnecessary personal information.
Trezor expressed profound disappointment in ShipMonk, claiming that the logistics provider had repeatedly provided written assurances that the data was being deleted in accordance with their contract and data policies. The fact that data from 2019 was still accessible in 2026 suggests a systemic failure in ShipMonk's data hygiene and a breach of trust between the manufacturer and its fulfillment partner.
The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks.
The technical catalyst: CVE-2026-72898
The breach was not the result of a direct attack on Trezor's internal systems, but rather a supply chain vulnerability. The entry point was a critical SQL injection flaw in Metabase, a third-party analytics platform used by ShipMonk. This vulnerability, identified as CVE-2026-72898, carried a maximum CVSS score of 10.0, indicating the highest level of severity.
By exploiting this zero-day flaw, attackers gained unauthorized access to systems holding customer-related data. According to the blockchain security firm Holborn, the breach is attributed to the ShinyHunters extortion gang. This group is known for targeting high-profile companies to steal sensitive data and subsequently demanding ransoms, turning a technical vulnerability into a financial leverage tool.
From digital phishing to physical threats
For the average consumer, a leaked email address is a nuisance. For a hardware wallet owner, it is a roadmap for targeted attacks. The specific knowledge that an individual owns a Trezor device allows bad actors to craft highly convincing social engineering campaigns. Attackers can move beyond generic spam to create urgent, personalized lures that mimic official support channels or financial institutions.
The inclusion of physical shipping addresses elevates the risk to what some in the community call 'IRL phishing'. With a home address and the knowledge of a high-value asset purchase, attackers can employ more aggressive tactics, such as sending fraudulent physical letters or even attempting courier impersonation. The goal remains the same: to trick the user into revealing their recovery seed phrase, the only piece of information that can actually compromise the funds on the device.
The systemic risk of the software supply chain
This incident highlights a growing trend in cyber warfare: the shift toward supply chain attacks. As primary targets like Trezor harden their own defenses, attackers target the secondary and tertiary vendors—logistics providers, analytics tools, or payment processors—who may have weaker security postures but hold the same sensitive data.
Holborn noted that this event underscores the necessity for organizations to maintain complete visibility into their third-party risk exposure. A company's security posture is only as strong as the least secure vendor in its ecosystem. In this case, a vulnerability in an analytics tool (Metabase) used by a shipping company (ShipMonk) ended up compromising the privacy of customers of a security company (Trezor).
Global business implications and regulatory outlook
For entrepreneurs and enterprises operating in the US and UK, the Trezor-ShipMonk incident serves as a critical case study in vendor management and liability. In the United Kingdom, the UK GDPR mandates strict controls over data processing and requires that data be kept only for as long as necessary. The revelation that data was retained years beyond the agreed-upon 90-day window could lead to significant regulatory scrutiny for the parties involved.
In the United States, while there is no single federal privacy law equivalent to the GDPR, state-level regulations like the CCPA in California grant consumers the right to request the deletion of their data. Companies that claim to delete data but fail to do so—especially when that data is subsequently leaked—face increasing legal risks and potential class-action lawsuits. For global businesses, the lesson is clear: contractual assurances of data deletion are insufficient. Continuous auditing and technical verification of a vendor's data disposal practices are now essential components of a robust risk management strategy.
Further details on the breach can be found via reports from The Hacker News and Decrypt.
FAQ
Were my cryptocurrency funds stolen in the Trezor breach?
No. The breach occurred at a shipping provider, not within Trezor's own systems. Private keys, seed phrases, and wallet backups were not compromised.
What specific data was leaked?
Depending on the customer, the leak included names, email addresses, phone numbers, shipping addresses, and order numbers.
How did the attackers get into the system?
They exploited a critical SQL injection vulnerability (CVE-2026-72898) in Metabase, an analytics platform used by the shipping partner ShipMonk.
What should I do if I am an affected customer?
Be extremely vigilant against phishing emails, fake phone calls, or physical letters. Never share your recovery seed phrase with anyone, regardless of how official they seem.
Sources: Thehackernews, Yahoo, Breachhistory ·
Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.
Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.
oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email



