Published September 10, 2026 - Prague, Czech Republic. Trezor, the hardware cryptocurrency wallet manufacturer, confirmed on September 4, 2026 that a data breach at its logistics partner ShipMonk is substantially larger than first reported, with about 67,000 additional U.S. customers exposed, bringing the total impact above 80,000 (Cybersecurity News, September 4, 2026). Attackers exploited a critical SQL injection zero-day in the Metabase analytics platform used by ShipMonk. Trezor devices themselves remain secure, and no wallet backups or recovery seeds were exposed. The risk to affected customers is targeted phishing and social engineering using the breached contact data, not direct theft of cryptocurrency.
Breach data last verified September 10, 2026 from Cybersecurity News (September 4, 2026) and the official Trezor support portal (trezor.io/support).
Quick Answer
The Trezor ShipMonk breach expanded on September 4, 2026 with 67,000 additional U.S. customers exposed, bringing the total impact above 80,000 customers. Attackers exploited a Metabase SQL injection zero-day on ShipMonk's unpatched instance. Trezor devices, wallet backups, and recovery seeds were NOT compromised. Affected customers should be alert to phishing campaigns using the breached contact data, never share recovery seeds, and verify all support interactions through the official Trezor channels. Trezor is preparing an Anonymous Delivery option to mitigate future exposure.
What Was Exposed
The first disclosure on August 13, 2026 covered 11,742 customers whose names, emails, phone numbers and shipping addresses were fully exposed, plus 1,947 with partial exposure of name, city and email, totaling about 13,689 people (Cybersecurity News, September 4, 2026). Those records were linked to orders in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal between May 10 and August 8, 2026. An August 14 update already admitted that some partial-exposure records included older orders.
The September 4 update added 67,000 additional U.S. customers from a prior ShipMonk partnership between November 2019 and August 2021. The newly acknowledged U.S. files include name, email, phone number, shipping address, and order number. The total impact is now above 80,000 customers globally.
What Was Not Exposed
Trezor's own systems were not breached, its devices remain secure, and wallet backups were not leaked (Cybersecurity News, September 4, 2026). Parcel contents were not exposed. No recovery seeds, PINs, passphrases, or any on-device cryptographic material were exposed. The breach was limited to order-handling data held by ShipMonk - the logistics company that ships Trezor devices from warehouse to customer.
Customers' cryptocurrency holdings remain safe as long as the recovery seed has not been shared with anyone or typed into a website. The risk from this breach is targeted phishing and social engineering using the exposed contact data, not direct theft of cryptocurrency.
The Metabase Zero-Day
ShipMonk told customers that attackers exploited a vulnerability in the analytics platform Metabase (Cybersecurity News, September 4, 2026). Metabase notified the logistics firm on August 6, 2026 that an unauthorized party used a software flaw to reach account and customer data. Later reporting tied the campaign to a critical SQL injection zero-day that yielded administrator access on compromised Metabase instances.
The vulnerability affected self-hosted Metabase deployments that had not applied the August 2026 security patch, and ShipMonk was running an unpatched instance at the time of the attack. The zero-day is a separate vulnerability from CVE-2026-0768 (the Langflow zero-day exploited in AI development infrastructure) and represents a different class of supply-chain risk: third-party SaaS tools that hold customer data without being on the security team's patch-management radar.
Trezor's Response
Trezor is preparing an Anonymous Delivery option with locker pickup and automatic deletion of shipping identifiers as a direct response to the breach (Cybersecurity News, September 4, 2026). This is the first incident since Trezor's 2013 founding to expose customer phone numbers and shipping addresses. The Anonymous Delivery option will let customers pick up their Trezor device from a third-party locker without sharing a home or office address with the logistics provider, and the locker system will automatically delete the shipping identifier after delivery confirmation.
Trezor is also working with ShipMonk to improve ShipMonk's data retention practices. Trezor requires fulfillment partners to delete or anonymize order data 90 days after delivery, and the older U.S. records should not have been in ShipMonk's systems at the time of the breach. Trezor said it repeatedly requested and received written assurance that ShipMonk had deleted the older records, yet the data was still in ShipMonk's systems.
What Affected Customers Should Do
Trezor customers affected by the ShipMonk breach have been emailed from [email protected]; anyone who did not receive that message is not in the leaked set (Cybersecurity News, September 4, 2026). Recipients should treat urgent requests for personal data as hostile, verify claims only through official Trezor channels, and never type a wallet backup into a website or share it with anyone.
Hardware-wallet recovery seeds should never be shared, photographed, or entered into any website under any circumstances. Trezor staff will never ask for a recovery seed, and neither will legitimate customer support. Phishing campaigns using the breached contact data to pose as Trezor support are the primary risk; users should bookmark the official Trezor site and only interact through that bookmark, not through email or text message links. Hardware-wallet users who have stored their recovery seed offline (the recommended practice) face no direct theft risk from this breach - the cryptographic keys never left their device.
Verify current breach notifications and account security status on the official Trezor support portal at trezor.io/support. Phishing awareness guidance is available from the Anti-Phishing Working Group at apwg.org.
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read more
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









