NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
LatestDaily BriefMarkets
NewsLayer PulseLIVE₿BTC$79,367-0.57%ΞETH$2,496+0.22%◎SOL$104.37-1.05%✕XRP$1.4-0.54%ÐDOGE$0.0905+1.08%₳ADA$0.221+0.89%Total Cap$2.82T-0.39%24H Vol$130.0BLayer Index40 Neutral
BreakingLiquid Hackers Return $270M in Bitcoin After Swiping $320 Million39 dakika önce
Markets
HomeCrypto

Crypto

Trezor’s Supply Chain Cracked Through ShipMonk’s Unpatched Metabase: 67,000 Crypto Customers Exposed

On September 2, Trezor learned that a breach at its fulfillment partner ShipMonk was larger than initially reported. Another 67,000 U.S. customers had their personal data exposed—names, email addresses, phone numbers, shipping…

forkast.news

Publisher

Sep 7, 2026 at 6:36 PM UTC · 2 dk okuma

Trezor’s Supply Chain Cracked Through ShipMonk’s Unpatched Metabase: 67,000 Crypto Customers Exposed
Image via forkast.news
Çevriliyor…

On September 2, Trezor learned that a breach at its fulfillment partner ShipMonk was larger than initially reported. Another 67,000 U.S. customers had their personal data exposed—names, email addresses, phone numbers, shipping addresses, and order numbers—bringing the total to roughly 80,689. The affected orders span November 2019 to August 2021. Trezor’s devices were not compromised. The attack went through ShipMonk’s systems, specifically a Metabase instance that ShipMonk ran on the public internet.

The entry point was CVE-2026-72898, an unauthenticated SQL injection in Metabase’s password reset endpoint carrying a CVSS score of 10.0. Metabase published the advisory on August 6. By August 11, CISA had added the vulnerability to its Known Exploited Vulnerabilities catalog with confirmed ransomware use.

The mechanics are straightforward. The /api/session/reset_password endpoint allowed unauthenticated SQL injection into Metabase’s application database, granting administrator access. From there, attackers could change application configuration, steal stored credentials for connected databases, and export data. Horizon3 estimated roughly 4,309 of 11,000 internet-exposed Metabase instances were likely vulnerable. ShipMonk’s was one of them.

Article Intelligence

Topics

crypto

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium
NewsLayer.com

The front page of the onchain economy. Crypto, Web3 and regulation intelligence — live prices, original research and policy tracking in one layer.

Follow on XTelegram

News

  • Latest News
  • The Daily Brief
  • Crypto
  • DeFi
  • Policy
  • Web3
  • Blockchain
  • Explainers

Markets

  • Market News
  • Layer Index
  • Live Charts
  • DeFi Protocols
  • Regulation Tracker
  • Regulation Radar

Company

  • About NewsLayer
  • Advertise
  • PR Publication
  • Become an Author
  • Our Authors
  • Create Account
  • Sign in

Resources

  • Research
  • NewsLayer Originals
  • My Feed
  • Search
  • AI Sector
  • Quantum Sector

NewsLayer Premium

Read the full layer.

Unlock premium intelligence, original research and an ad-free reading experience.

  • Premium Intelligence briefings
  • Ad-free reading experience
  • Members-only research & data
Go Premium

© 2026 NewsLayer.com — The front page of the onchain economy

Privacy Policy·Terms of Service
NewsLayer

Get the signal, not the noise.

Markets, regulation and onchain intelligence in a 5-minute morning read — plus breaking alerts and Layer Index flips as they happen.

The Daily Brief

Breaking alerts

Index flips

Free · No spam · Unsubscribe anytime