In short: Hardware cryptocurrency wallet maker Trezor has confirmed a data breach affecting 13,689 customers across seven countries. Attackers exploited a critical zero-day vulnerability, CVE-2026-72898 (CVSS 10.0), in the Metabase business intelligence platform used by Trezor's logistics partner ShipMonk. Stolen data includes names, delivery addresses, phone numbers, and email addresses. Trezor wallets and crypto assets are safe — the risk is targeted phishing using the stolen contact details.
What Happened
On August 6, 2026, Metabase notified its customers about unauthorized access through a zero-day vulnerability in its analytics platform. Among those affected was ShipMonk, a fulfillment operator processing Trezor orders in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. By the time the notification went out, the data had already been stolen — the attack predated any available fix.
ShipMonk notified Trezor on August 10. On August 13, Trezor publicly disclosed the incident, noting it was the first breach in the company's history since 2013 to involve customers' phone numbers and delivery addresses — a significantly more sensitive data category than email addresses alone.
CVE-2026-72898: A CVSS 10.0 Zero-Day SQL Injection in Metabase
The vulnerability scored the maximum CVSS rating of 10.0 (Critical). The flaw resided in Metabase's password-reset mechanism: an unauthenticated attacker could submit a crafted request to trigger a SQL injection, ultimately obtaining full database administrator privileges without ever providing valid credentials. This is a textbook supply chain attack: rather than targeting Trezor directly, hackers went after a third-party vendor that stored sensitive customer data on Trezor's behalf. For context on how such attacks unfold, see our coverage of recent cybersecurity incidents.
When Metabase sent breach notifications on August 6, it was already too late. A zero-day by definition means no patch existed when the attack occurred. ShipMonk had no opportunity to apply a fix that had not yet been released.
What Was Stolen and Who Is Affected
The breach covers 13,689 customers who placed orders through ShipMonk between May 10 and August 8, 2026:
- 11,742 customers — fully compromised: name, email address, phone number, and full delivery address.
- 1,947 customers — partially compromised: name, city, and email address.
Affected customers are located in seven countries: the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Payment card data, seed phrases, and crypto assets were not stolen. Hardware wallets continue to operate normally and all funds remain secure.
Why Name, Address, and Phone Make Phishing Attacks More Dangerous
Trezor immediately warned affected customers of an elevated risk of targeted phishing attacks. The combination of a name, physical address, and phone number enables far more convincing fraud than an email-only breach ever could:
- Phishing emails from fake "Trezor support" or a "shipping carrier" asking you to confirm your address or verify your wallet.
- SMS and phone calls from supposed "bank security" or "Trezor customer service" about a suspicious transaction.
- Vishing (voice phishing): attackers recite your name and address to appear legitimate, then pressure you into revealing your seed phrase.
The seed phrase is the single key that recovers a hardware wallet. Anyone who obtains it gains complete, irreversible control over all funds. Trezor will never ask for your seed phrase by email, SMS, or phone — any such request is fraud. For a closer look at social engineering tactics used in these scams, read our post on remote access fraud.
How to Protect Yourself
If you purchased a Trezor device between May 10 and August 8, 2026. Trezor is sending email notifications — check your spam folder. Over the coming weeks, treat any email, SMS, or call claiming to be from Trezor, ShipMonk, or a shipping carrier with extreme caution. Never share your seed phrase with anyone, regardless of how legitimate they appear.
General digital hygiene steps. Use unique email addresses for different services to limit the impact of any single breach. Enable two-factor authentication (2FA) on crypto exchanges, email accounts, and other important services. When connecting on public networks — in cafés, airports, or shopping centers — use LiMP VPN to encrypt your traffic and mask your IP address, protecting sessions and reducing network-level exposure. This matters especially when accessing crypto exchanges or online banking away from home.
Keep in mind: a VPN cannot prevent a data breach on a third-party server — that is a responsibility for the companies storing your data. But LiMP VPN with its strict no-logs policy protects your traffic and privacy at the network layer — the part you actually control.
