Trezor·Crypto / Web3·
Customer personal information was compromised.
Trezor said ShipMonk unauthorized access exposed names, contact details, and shipping addresses for nearly 14,000 customers. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- First publicly reported
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: SQL injection flaw in Metabase password-reset endpoint
- Consequence
- Reported: Customer personal information was compromised.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Trezor
- Industry
- Crypto / Web3
- Disclosed
- Third party
- ShipMonk
- Affected asset
- Trezor customer order data
- Product / vendor
- Metabase
- Data involved
- Personal data
- Reported impact
- Data exposure
- Attached evidence
- 8 independent domains · 8 sources
2)Evidence-backed incident path
- 01
Reported cause
SQL injection flaw in Metabase password-reset endpoint
ConfidenceSecondaryExact excerpt
E1“an SQL injection flaw in the platform’s /reset_password endpoint”
halborn.com · Aug 26 - 02
Third party
ShipMonk
ConfidenceSecondaryExact excerpt
E2“one of our shipping providers, ShipMonk”
bleepingcomputer.com · Aug 13 - 03
Affected product
Metabase
ConfidenceSecondaryExact excerpt
E3“the third-party analytics platform Metabase”
bleepingcomputer.com · Aug 13 - 04
Reached
Trezor customer order data
ConfidenceSecondaryExact excerpt
E4“attackers gained access to customers' order data”
bleepingcomputer.com · Aug 13 - 05
Observed
Customer personal information was compromised.
ConfidenceProbableExact excerpt
E5“personal information of nearly 14,000 people was compromised”
securityweek.com · Aug 14
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- Regulatory action or customer remediation is not established
- That a Defence review would have prevented this incident
4)Relevance to your product
Third-party access can inherit more reach than the product team intended.
This pattern applies when…
- Products that share order or customer data with fulfillment providers.
- Teams that assess vendor access to customer records.
Diagnostic questions
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
This incident does not establish your product's risk.
5)Sector context — Crypto / Web3
- 0 incident threads
- 1 incident threads
- 1 incident threads
- 0 incident threads
- 15 incident threads
- 15 incident threads
- 6 incident threads
- 15 incident threads
- 17 incident threads
- 14 incident threads
- 16 incident threads
- 26 incident threads
- Same incident family
- 6 Supply chain / third party
- Confirmed share
- 14% 18 confirmed · 108 reported
- Display family
- Supply chain Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Crypto / Web3 in Radar →6)Defence control mapping
What Defence can test
Third-party integration review
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
8 attached sources across 8 independent domains. No attached source is marked as an organization or regulator primary source.
- E5securityweek.com14000 Trezor Customers Impacted by Data Breach at ...Specialist reporting · Aug 14 · CitedSpecialist reportingCited
Exact excerpt
“personal information of nearly 14,000 people was compromised”
- E1halborn.comExplained: The Trezor/ShipMonk Breach (August 2026)Other public report · Aug 26 · CitedOther public reportCited
Exact excerpt
“tracked as CVE-2026-72898”
- E2, E3, E4bleepingcomputer.comTrezor discloses data breach affecting nearly ...Specialist reporting · Aug 13 · CitedSpecialist reportingCited
Exact excerpt
“full names, shipping addresses, email addresses, and phone numbers”
Show all 8 sourcesShow the first six sources
Does this integration boundary exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.