Trezor Data Breach: 13,689 Customers Exposed via Critical Metabase Zero-Day CVE-2026-72898
The personal data of nearly 14,000 Trezor hardware wallet customers was stolen by exploiting a critical zero-day vulnerability in Metabase, the business intelligence platform used by Trezor’s logistics partner ShipMonk. The incident drew immediate attention from the blockchain security community, and the details reveal a supply-chain exposure that Trezor itself had no power to prevent in real time.
The Vulnerability: CVE-2026-72898 – CVSS 10.0 Critical
Attackers exploited CVE-2026-72898, a vulnerability carrying the maximum CVSS score of 10.0. The flaw permitted unauthenticated SQL injection through Metabase’s password-reset mechanism, enabling a remote attacker to escalate directly to administrator-level privileges without any prior authentication. At the time of exploitation, the vulnerability was unknown to Metabase’s developers – a true zero-day – and was being actively weaponized in the wild before any patch existed.
A Wave of Attacks Across Multiple Organizations
The first documented exploitation occurred on August 2. By August 3, the same vulnerability had been turned against Framework and Tally. Subsequent victims included Kilo Code, n8n, Checkly, and ShipMonk. Metabase detected the intrusions against its own cloud platform and issued a public warning alongside remediation updates on August 6.
ShipMonk informed its clients that Metabase had notified the company of the unauthorized access on August 6. By that point, however, the data had already been exfiltrated. ShipMonk had no opportunity to apply an available patch before the attack occurred. Following Metabase’s notification, the vulnerability was closed and all active sessions were invalidated. ShipMonk subsequently launched a forensic investigation with the assistance of external specialists.
Trezor Notified on August 10 – Customers Alerted Days Later
Trezor learned of the incident from ShipMonk on August 10, 2026. Within days, the hardware wallet manufacturer notified affected customers directly. On August 11, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-72898 to its Known Exploited Vulnerabilities catalog and directed federal agencies to remediate the issue by August 14.
Scope of the Breach: What Was Exposed
The full data set – comprising name, email address, phone number, and delivery address – was exposed for 11,742 Trezor customers. An additional 1,947 individuals had partial data compromised, consisting of name, city, and email address. In total, the breach affected approximately 13,689 customers.
According to Trezor, the majority of those affected had placed orders between May 10 and August 8, 2026, across the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The company separately cautioned that the 1,947 customers with partially exposed data may include holders of older orders.
Why the Breach Was Not Larger: Trezor’s Data Retention Policy
The scale of the exposure was constrained not by ShipMonk’s security controls, but by Trezor’s own data retention requirements. Trezor mandates that order information be deleted or anonymized within 90 days of delivery, and extends that obligation to its logistics partners. Because of this short retention window, the bulk of older order records no longer existed within ShipMonk’s systems at the time of the attack.
Trezor’s core systems, hardware wallets, and services were not compromised in any way.
Why This Breach Is Particularly Dangerous for Crypto Users
The combination of a name, phone number, and home address belonging to a cryptocurrency wallet owner represents a substantially more serious threat than a conventional email leak. These details equip fraudsters to craft highly convincing phishing messages and phone calls, dispatch counterfeit delivery notifications, and impersonate Trezor, banks, or cryptocurrency exchanges with alarming plausibility.
ShipMonk also received extortion correspondence from the ShinyHunters threat group. Whether that group was directly involved in exploiting CVE-2026-72898 and stealing the Trezor customer data has not yet been established.
Trezor’s Guidance for Affected Customers
Trezor advises affected customers to exercise heightened vigilance toward any calls, messages, or parcels that reference their order. The company also recommends enabling a SIM-swap protection PIN with their mobile carrier where that feature is available. Under no circumstances should a wallet’s recovery seed phrase be entered on any website or shared with any individual. Neither Trezor, nor a bank, nor a cryptocurrency exchange will ever request this information.
All known affected customers were notified by email from help@trezor.io. Trezor states that users who did not receive that message were not affected by the breach. The final tally of impacted individuals may still rise, as ShipMonk continues to refine its assessment of the scope and retention period of the partially exposed data.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.