In August 2026, Trezor was the victim of a supply chain attack. A breach of the hardware wallet company’s providers resulted in the exposure of the shipping addresses and other personal data of about 14,000 of its customers.
Inside the Breach
The Trezor hack doesn’t impact the security of the company’s hardware wallets. However, it does open the door to social engineering attacks, in which the attackers can impersonate the company in email communications and include realistic details to increase the believability of their pretexts.
Trezor was notified on August 10, 2026 by its shipping provider, ShipMonk, that its customer data was exposed. Of the nearly 14,000, 11,742 customers had their names, phone numbers, emails, and shipping addresses leaked. Another 1,947 customers had partial data exposure. This incident didn’t affect customers who ordered via Amazon though, since these orders used a different logistics provider.
ShipMonk, in turn, was notified a few days earlier of a vulnerability in Metabase, an analytics platform used by the company. The issue was an SQL injection flaw in the platform’s /reset_password endpoint that is tracked as CVE-2026-72898 and rated as a 10.0 on the CVSS scale. A failure to restrict undeclared fields in the password reset request body allowed the attacker to inject malicious SQL into the database and gain full administrator control over it. The flaw was first exploited as a zero-day on August 3 and publicly disclosed and patched a week later.
The attacker exploited the public-facing Metabase application and used the SQL vulnerability to escalate to full administrator access and steal sensitive customer data. Later, ShinyHunters sent extortion emails to ShipMonk.
Lessons Learned from the Breach
The Trezor breach was the result of a supply chain attack beginning with a zero-day vulnerability. By finding and exploiting the SQL injection flaw in Metabase, the attackers were able to exploit several of its customers, stealing sensitive data and extorting the organization. In Trezor’s case, this meant the exposure of customer order details that were stored in a Metabase instance by ShipMonk.
Supply chain attacks are increasingly common, and organizations need visibility into their third-party risk exposure to help manage their overall security posture. Halborn offers Risk Assessment services to help organizations gain a holistic view of their security maturity, including threats across technology, people and processes. To learn more about protecting your organization, get in touch with Halborn.
