On September 2, Trezor learned that a breach at its fulfillment partner ShipMonk was larger than initially reported. Another 67,000 U.S. customers had their personal data exposed—names, email addresses, phone numbers, shipping addresses, and order numbers—bringing the total to roughly 80,689. The affected orders span November 2019 to August 2021. Trezor’s devices were not compromised. The attack went through ShipMonk’s systems, specifically a Metabase instance that ShipMonk ran on the public internet.
Trezor’s Supply Chain Cracked Through ShipMonk’s Unpatched Metabase: 67,000 Crypto Customers Exposed
On September 2, Trezor learned that a breach at its fulfillment partner ShipMonk was larger than initially reported. Another 67,000 U.S. customers had their personal data exposed—names, email addresses, phone numbers, shipping…
forkast.news
Publisher
Sep 7, 2026 at 6:36 PM UTC · 2 分钟阅读

The entry point was CVE-2026-72898, an unauthenticated SQL injection in Metabase’s password reset endpoint carrying a CVSS score of 10.0. Metabase published the advisory on August 6. By August 11, CISA had added the vulnerability to its Known Exploited Vulnerabilities catalog with confirmed ransomware use.
The mechanics are straightforward. The /api/session/reset_password endpoint allowed unauthenticated SQL injection into Metabase’s application database, granting administrator access. From there, attackers could change application configuration, steal stored credentials for connected databases, and export data. Horizon3 estimated roughly 4,309 of 11,000 internet-exposed Metabase instances were likely vulnerable. ShipMonk’s was one of them.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
