Desk live·
ForensicPost
Breaches/Supply chain/File 26-0813b

Trezor Says 13,689 Buyers Were Exposed by Its Shipping Partner, via the Metabase Flaw

The hardware wallet maker’s shipping provider, ShipMonk, was reached through the Metabase vulnerability filed at 26-0811. Names, phone numbers and home addresses of people who bought a device for holding cryptocurrency were taken.

Constructed geometry · not a chart of case data
JurisdictionCzechiaPraguethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTrezor customers via ShipMonk
ActorUnattributed
S. Rosler10 min readConfidence: high3 sources reviewed

On 13 August 2026 Trezor disclosed that 13,689 of its customers were affected by a breach at ShipMonk, the logistics provider that ships its hardware wallets. For 11,742 people the exposure covers name, email address, phone number and shipping address; for another 1,947 it is limited to name, city and email. Orders placed between 10 May and 8 August 2026 are in scope, across the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

The chain runs four organisations deep. Metabase, an analytics platform, told ShipMonk on 6 August that an unauthorised party had exploited a flaw in its software to reach data tied to ShipMonk’s account. ShipMonk told Trezor on 10 August. Trezor told its customers on the 13th. The flaw is the Metabase zero-day this database filed at 26-0811, which had already reached five companies before disclosure — this file records its arrival at the people standing at the end of the chain.

The Device Never Mattered

Trezor states its own systems were untouched and no customer device was compromised. Both statements are plausible and neither is the point. A hardware wallet exists to keep signing keys off any network, and the protection worked exactly as designed.

What leaked is the customer list — and a hardware wallet customer list is a directory of people known to hold bearer assets, annotated with where they live. The corpus recorded at 25-0530 what that combination is worth: Coinbase put a nine-figure estimate on remediation after its support data reached attackers, because each record is a qualified lead for a fraud with an irreversible settlement mechanism.

A Shipping Label Is A Security Boundary

Nobody in this chain mishandled the data by the standards of their own business. A fulfilment provider needs names and addresses to ship parcels; an analytics platform needs access to the data it analyses. Each link was ordinary.

The composition is what failed. A customer who bought a security device from a security company was exposed by an analytics tool used by a warehouse they had never heard of. No purchase decision available to them touched any link in that chain, and the notification letter they received is from the one company in it they chose.

What The Letter Can And Cannot Fix

Trezor’s advice to affected customers is to expect convincing phishing that quotes real order details, and never to enter a recovery seed anywhere a message asks. That is the right advice, and it addresses the smaller half of the exposure. An address does not expire and cannot be rotated. For a subset of holders, the risk that follows a published address is physical, and no mailing-list remedy speaks to it.

How we reported this

Compiled from Trezor’s customer notice and contemporaneous reporting, listed below. The per-tier counts and order window are the company’s. The identification of the Metabase flaw as the route is as stated by ShipMonk via Trezor’s account and reporting of it. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Recent customer data exposed in shipping provider incidentTrezor
  2. Trezor discloses data breach affecting nearly 14,000 customersBleepingComputer
  3. Trezor discloses data breach affecting nearly 14,000 customers after shipping partner hackteiss
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary