August 13, 2026. Trezor announces a data breach at its fulfillment partner ShipMonk. 13,689 customers affected. Names, emails, phone numbers, shipping addresses. The company blames a SQL injection in ShipMonk's Metabase instance. It points to the 90-day data deletion policy it negotiated with ShipMonk as the reason the damage was contained. Only orders from May 10 to August 8, 2026 were exposed. Older data, Trezor assured everyone, had already been deleted.
Fast-forward to September 4, 2026. A Friday news dump that should make every Trezor customer ask a harder question: "What else have I been told that isn't true?"
Trezor dropped the update in a single sentence: another approximately 67,000 US customers had their personal information exposed in the same ShipMonk breach. [[4]] The records date back to 2019 and 2021 — orders placed nearly seven years ago. [[20]] Total affected users now stands at roughly 80,700. [[16]]
That 90-day deletion policy Trezor kept referencing? It was never enforced. Trezor says it received written assurances from ShipMonk. Multiple times. [[18]] The data stayed anyway. And now every single piece of identifying information those customers handed over — name, address, phone number, email, order number — is in the hands of the attackers.
Code doesn't care about your feelings. And apparently, neither do written guarantees from third-party logistics providers.
The Attack Chain: A CVSS 10.0 Zero-Day That Hit Three Companies at Once
Let's trace the kill chain because the technical details matter more than the apology statements.
The breach originated at ShipMonk, a fulfillment provider that stores Trezor inventory and ships parcels to customers across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. [[7]] ShipMonk runs a self-hosted instance of Metabase, an open-source analytics platform. On or before August 6, 2026, an attacker exploited CVE-2026-72898 — a critical unauthenticated SQL injection vulnerability in Metabase rated CVSS 10.0. [[33]]
That is not a typo. CVSS 10.0. The maximum severity score.
The attacker used the SQL injection to escalate privileges to full administrative access on ShipMonk's Metabase instance. [[27]] From there, they exfiltrated customer order data — names, shipping addresses, phone numbers, email addresses, order numbers. [[2]] The same vulnerability also hit laptop manufacturer Framework and form-builder Tally, both of whom also used self-hosted Metabase instances. [[30]]
The ShinyHunters extortion gang later sent extortion emails to ShipMonk. [[30]] Horizon3 published a proof-of-concept exploit. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog. [[33]]
Metabase patched the issue and invalidated active sessions. [[30]] But the patch came after the data was already stolen. The damage was done.
ShipMonk notified Trezor on August 10, 2026. [[7]] Trezor disclosed publicly on August 13. [[7]] Then on September 2, ShipMonk came back with more bad news: the breach went deeper than originally reported. [[16]]
The 90-Day Deletion Lie: A Case Study in Trust Theater
Here is the part that should make every security professional wince.
Trezor's fulfillment partners are contractually required to delete or anonymize customer order data 90 days after delivery. [[41]] Trezor told the public this policy limited the breach to recent orders. The company even framed it as a feature: "Only orders received within 90 days before August 8th, 2026, were affected, as older data had already been deleted." [[41]]
That statement was false. Trezor just didn't know it yet.
The newly discovered records span from November 2019 through August 2021. [[23]] Those orders should have been purged years ago. Trezor says it repeatedly requested and received written assurances from ShipMonk confirming the deletion was performed. [[18]] The assurances were worthless.
This is what I call "trust theater" — a contractual clause that looks good in a pitch deck or a blog post but has zero technical enforcement. Trezor had no way to verify that ShipMonk actually deleted the data. No audit mechanism. No automated verification. Just a PDF from a vendor saying "we promise."
Based on my audit experience, I have seen this pattern at least a dozen times across different crypto infrastructure providers. A company negotiates a data retention clause with a vendor. The vendor signs it. Nobody checks whether the vendor actually implements it. Then a breach happens, and the company discovers the clause was never operationalized.
The failure mode here is structural. Trezor's data deletion policy existed on paper but not in ShipMonk's database infrastructure. And because Trezor had no independent verification mechanism — no read-only query access, no periodic third-party audit, no automated expiration enforcement — the policy was effectively a marketing claim, not a security control.
The Real Risk Isn't Your Crypto — It's Your Front Door
Trezor has been careful to state that its own systems were not compromised. The hardware wallets are secure. Private keys and seed phrases were not exposed. [[17]]
That is technically true. It is also dangerously incomplete.
The exposed data includes names, home addresses, phone numbers, and email addresses of verified hardware wallet owners. [[16]] This is not a random list of email addresses scraped from a forum. This is a surgically precise target list that tells attackers: "This person owns a cryptocurrency hardware wallet. This is where they live. This is their phone number."
CertiK verified 52 physical attacks on crypto holders worldwide in the first half of 2026, up from 39 in the same period last year. [[45]] Chainalysis put the amount stolen through violent attacks at more than $30 million over the same period. [[1]] Home invasions have overtaken kidnapping as the most common method. [[36]]
Panic sells, liquidity buys. But there is no liquidity trade for physical security.
The phishing risk is equally severe. In April 2025, attackers used leaked Ledger order data to send physical letters with fake Ledger and Trezor merger announcements, complete with QR codes and forged executive signatures. [[24]] Recipients were instructed to scan the code and enter their 24-word recovery phrase under the guise of a "critical security update." [[5]]
Trezor's affected customers should expect the same treatment — but worse, because the attackers now have phone numbers and physical addresses, enabling cross-channel attacks. A convincing phone call followed by a follow-up email, followed by a physical letter, all referencing the customer's real order history. The attack surface is three-dimensional.
ShipMonk Held SOC 2 Type II Certification. It Got Breached Anyway.
One detail that should reset how the industry thinks about vendor security: ShipMonk held SOC 2 Type II certification, an audited security standard. [[1]] It was breached regardless.
SOC 2 is not a guarantee of security. It is a snapshot of controls at a point in time. The Metabase instance was self-hosted, internet-facing, and running a version vulnerable to a critical zero-day. The certification did not prevent the exploitation. It did not detect the intrusion faster. It did not protect customer data.
The lesson is straightforward: compliance frameworks are necessary but not sufficient for security. They create a baseline, not a fortress. Any vendor handling crypto-adjacent personal data needs continuous monitoring, not annual certification.
Anonymous Delivery: The Right Move, Three Years Too Late
Trezor's response to the breach includes rolling out an "Anonymous Delivery" option. The feature uses a dedicated checkout, locker pickup, neutral unbranded packaging, generic sender details, and automatic deletion of shipping identifiers after delivery. [[24]] The EU rollout is targeted for September 2026. The US rollout is targeted for the end of 2026. [[24]]
This is the right architectural solution. It decouples the purchase of a hardware wallet from the disclosure of a home address. It limits the data exposure surface to what is strictly necessary for delivery. It is exactly the kind of data minimization that should have existed from the start.
But here is the problem: Trezor has been shipping hardware wallets for 13 years. [[39]] The company has now experienced two third-party data breaches — one in January 2024 affecting 66,000 support ticket users, and now this ShipMonk incident affecting 80,700 customers. [[5]]
Anonymous delivery should not have been a reactive measure. It should have been a design requirement from day one. The fact that it took two major breaches and over 146,000 exposed customer records to prioritize this feature tells me the incentive structure inside Trezor was misaligned. Security improvements only became urgent after the damage was already done.
The Unresolved Question: Will Trezor Drop ShipMonk?
As of September 4, 2026, Trezor has not announced plans to terminate its relationship with ShipMonk. [[40]] The company previously stated it would determine the partnership's future after obtaining a complete picture of the incident. [[40]] The known affected user count now approaches 80,700. The picture is complete enough.
If Trezor keeps ShipMonk as a fulfillment partner after this, it signals that cost and operational convenience outweigh customer security. If Trezor drops ShipMonk, it incurs switching costs and supply chain disruption but preserves whatever remains of its brand credibility.
Either way, the trust calculus has changed. Trezor built its reputation on keeping private keys safe. The company has less control, it turns out, over what its shipping partners do with customer mailing addresses. [[31]]
What This Means for the Industry
This incident is not an edge case. It is a structural pattern.
Ledger's payment processor Global-e leaked customer order data in January 2026. [[1]] Within days, attackers were sending phishing emails announcing a fake Ledger and Trezor merger, personalized with the leaked order details. [[1]] Now Trezor's fulfillment partner has leaked another 80,700 records.
The crypto hardware wallet industry has a supply chain security problem that no one is solving at the protocol level. Every vendor in the chain — payment processors, fulfillment centers, customer support platforms — becomes a potential attack vector. And the data these vendors hold is uniquely dangerous because it identifies high-value targets with their real-world identities and locations.
The industry needs a standardized approach to vendor data minimization. Encryption at rest is not enough if the vendor has the decryption keys. Data deletion clauses are not enough if nobody verifies they are executed. The only reliable approach is to design the data flow so that sensitive customer information never reaches third-party vendors in a form that is usable for attack.
Anonymous delivery is one piece of that puzzle. But the industry also needs better vendor security requirements, mandatory breach notification timelines with regulatory teeth, and independent verification of data retention policies.
The Bottom Line
Trezor is asking affected customers to trust that their crypto assets remain safe. That part is true — the hardware wallets themselves were not compromised. But trust is not binary. It is a vector with multiple components. Trezor has eroded trust in its ability to manage customer data, vet vendors, and enforce contractual security requirements.
The 90-day deletion promise was theater. The written assurances from ShipMonk were worthless. The breach notification timeline — ShipMonk notified Trezor on August 10, Trezor disclosed on August 13, then waited until September 4 to reveal the full scope — raises questions about transparency.
Anonymous delivery is coming. It should have been here years ago. The question Trezor customers need to ask themselves is not whether their private keys are safe. The question is whether a company that could not verify a basic data deletion clause from a fulfillment partner deserves custody of their home address, phone number, and order history.
Yield is the bait, rug is the hook. Except in this case, the yield was "convenience" and the rug was "we promise they deleted your data."
Survival is the only alpha. And survival, in this market, means treating every third-party data handoff as a potential compromise — because eventually, it will be.