Trezor, the hardware wallet maker, disclosed on 4 September that a breach at its shipping vendor ShipMonk exposed about 67,000 additional US customers whose orders date from November 2019 to August 2021, on top of the 13,689 customers it notified in August.1 Trezor 2026-09-04 Timeline 10, 13, 14 August, 2 and 4 September; 13,689 in the first disclosure; about 67,000 additional US customers; fields exposed; no device or key exposure; written deletion assurances; Anonymous Delivery option planned. Open source 2 The Hacker News 2026-09-05 Data from November 2019 to August 2021; CVE-2026-72898 in Metabase at CVSS 10.0; ShipMonk silent publicly; Holborn attribution to ShinyHunters; deletion assurances. Open source The older data should not have existed: Trezor says it repeatedly requested and received written assurance from ShipMonk that it had been deleted under their contract.1 Trezor 2026-09-04 Timeline 10, 13, 14 August, 2 and 4 September; 13,689 in the first disclosure; about 67,000 additional US customers; fields exposed; no device or key exposure; written deletion assurances; Anonymous Delivery option planned. Open source The intrusion used CVE-2026-72898, a critical SQL injection zero day in the Metabase analytics platform rated CVSS 10.0, and the blockchain security firm Holborn attributes it to the ShinyHunters extortion group.2 The Hacker News 2026-09-05 Data from November 2019 to August 2021; CVE-2026-72898 in Metabase at CVSS 10.0; ShipMonk silent publicly; Holborn attribution to ShinyHunters; deletion assurances. Open source The exposed fields are names, emails, phone numbers, shipping addresses and order numbers; no device contents, keys or backups were touched.1 Trezor 2026-09-04 Timeline 10, 13, 14 August, 2 and 4 September; 13,689 in the first disclosure; about 67,000 additional US customers; fields exposed; no device or key exposure; written deletion assurances; Anonymous Delivery option planned. Open source Our assessment, with high confidence, is that the security failure here is contractual, not technical: a deletion certificate is not a deletion. With moderate confidence, we assess the real risk to the 80,000 people as physical and social rather than digital, because a shipping address plus a hardware wallet order is a target list.
The timeline, and what it reveals
Metabase notified ShipMonk of unauthorized access on 6 August. ShipMonk told Trezor on 10 August. Trezor disclosed on 13 August and updated the next day, covering orders from 10 May to 8 August 2026 across seven countries.1 Trezor 2026-09-04 Timeline 10, 13, 14 August, 2 and 4 September; 13,689 in the first disclosure; about 67,000 additional US customers; fields exposed; no device or key exposure; written deletion assurances; Anonymous Delivery option planned. Open source 3 Cyber Security News 2026-09-04 Total above 80,000; Metabase notified ShipMonk 6 August; full timeline; customer guidance; locker pickup and automatic deletion of shipping identifiers. Open source On 2 September ShipMonk disclosed a larger scope, and on 4 September Trezor confirmed that the larger scope was five year old data from a partnership that ended in August 2021.1 Trezor 2026-09-04 Timeline 10, 13, 14 August, 2 and 4 September; 13,689 in the first disclosure; about 67,000 additional US customers; fields exposed; no device or key exposure; written deletion assurances; Anonymous Delivery option planned. Open source 3 Cyber Security News 2026-09-04 Total above 80,000; Metabase notified ShipMonk 6 August; full timeline; customer guidance; locker pickup and automatic deletion of shipping identifiers. Open source ShipMonk has not publicly acknowledged the incident, per The Hacker News, though it is said to have secured the affected systems.2 The Hacker News 2026-09-05 Data from November 2019 to August 2021; CVE-2026-72898 in Metabase at CVSS 10.0; ShipMonk silent publicly; Holborn attribution to ShinyHunters; deletion assurances. Open source
Two things stand out. First, the gap between the first and second disclosures is three weeks, during which the vendor was presumably discovering how much old data it still held. Second, the old data was in a system reachable through an analytics tool. Metabase is a business intelligence layer that sits on top of databases; a SQL injection in it gives an attacker the database. Data kept for reporting is data kept for attackers.
Why a deletion certificate failed
Trezor's statement that it requested and received written deletion assurances is the center of the story.1 Trezor 2026-09-04 Timeline 10, 13, 14 August, 2 and 4 September; 13,689 in the first disclosure; about 67,000 additional US customers; fields exposed; no device or key exposure; written deletion assurances; Anonymous Delivery option planned. Open source 2 The Hacker News 2026-09-05 Data from November 2019 to August 2021; CVE-2026-72898 in Metabase at CVSS 10.0; ShipMonk silent publicly; Holborn attribution to ShinyHunters; deletion assurances. Open source Vendor data retention is governed, in practice, by contracts and attestations; almost no customer verifies that a vendor's backups, analytics replicas and warehouse tables have actually been purged. ShipMonk certified deletion and kept the data, whether through a retained backup, a reporting copy or simple failure, and Trezor had no way to know until an attacker showed it. For a company whose customers are, by definition, people holding cryptocurrency, that gap is the breach.
Trezor's remedy is structural rather than contractual: an Anonymous Delivery option with locker pickup and automatic deletion of shipping identifiers, targeted for the EU this month and the US by the end of 2026.1 Trezor 2026-09-04 Timeline 10, 13, 14 August, 2 and 4 September; 13,689 in the first disclosure; about 67,000 additional US customers; fields exposed; no device or key exposure; written deletion assurances; Anonymous Delivery option planned. Open source 3 Cyber Security News 2026-09-04 Total above 80,000; Metabase notified ShipMonk 6 August; full timeline; customer guidance; locker pickup and automatic deletion of shipping identifiers. Open source That is an admission that the only address a vendor cannot leak is one it never receives.
Who gains and who loses
The 80,000 or so affected customers lose the most, and not in the way a typical breach victim does.3 Cyber Security News 2026-09-04 Total above 80,000; Metabase notified ShipMonk 6 August; full timeline; customer guidance; locker pickup and automatic deletion of shipping identifiers. Open source A list of people who bought a hardware wallet, with home addresses, is a list of people who probably hold crypto and probably hold it at home. Trezor's guidance reflects this: treat urgent requests for personal data as hostile, verify through official channels, and never type a wallet backup into a website.3 Cyber Security News 2026-09-04 Total above 80,000; Metabase notified ShipMonk 6 August; full timeline; customer guidance; locker pickup and automatic deletion of shipping identifiers. Open source The risk is phishing tuned to the order number, and in the worst case, a knock on the door.
ShinyHunters gains a monetizable list and, if Holborn's attribution is right, another entry in a 2026 campaign that has already hit Kodak, Telus and others.2 The Hacker News 2026-09-05 Data from November 2019 to August 2021; CVE-2026-72898 in Metabase at CVSS 10.0; ShipMonk silent publicly; Holborn attribution to ShinyHunters; deletion assurances. Open source Trezor loses trust with the one customer base for which trust is the product, though the hardware itself was never at risk.1 Trezor 2026-09-04 Timeline 10, 13, 14 August, 2 and 4 September; 13,689 in the first disclosure; about 67,000 additional US customers; fields exposed; no device or key exposure; written deletion assurances; Anonymous Delivery option planned. Open source ShipMonk loses whatever a logistics provider loses when a client says in public that it lied about deletion, and its silence makes that worse.2 The Hacker News 2026-09-05 Data from November 2019 to August 2021; CVE-2026-72898 in Metabase at CVSS 10.0; ShipMonk silent publicly; Holborn attribution to ShinyHunters; deletion assurances. Open source Metabase carries a CVSS 10.0 zero day into its next sales conversation. Every company that has ever received a deletion certificate from a vendor loses the comfort of believing it.
The counter case
The assessment that the risk is physical could be overstated. The exposed data is five to seven years old for the newly disclosed cohort, and many of those addresses are stale; a 2019 buyer may have moved, sold or lost interest in crypto.2 The Hacker News 2026-09-05 Data from November 2019 to August 2021; CVE-2026-72898 in Metabase at CVSS 10.0; ShipMonk silent publicly; Holborn attribution to ShinyHunters; deletion assurances. Open source Phishing is the likelier harm and is bounded by the fact that a hardware wallet cannot be drained by email alone unless the owner types a seed phrase into a website, which is exactly what Trezor is warning against.3 Cyber Security News 2026-09-04 Total above 80,000; Metabase notified ShipMonk 6 August; full timeline; customer guidance; locker pickup and automatic deletion of shipping identifiers. Open source The attribution to ShinyHunters comes from a single security firm and has not been confirmed by ShipMonk or law enforcement.2 The Hacker News 2026-09-05 Data from November 2019 to August 2021; CVE-2026-72898 in Metabase at CVSS 10.0; ShipMonk silent publicly; Holborn attribution to ShinyHunters; deletion assurances. Open source And the contractual failure, while real, is not unusual: the unusual part is that Trezor said so publicly, which may make it look worse than peers who would have said less.
What to watch
- Extortion or leak posting. If the data appears on a ShinyHunters leak site or is used in a documented phishing wave against Trezor customers within two months, the harm is realized; no public appearance would suggest a quiet sale or a bluff.2 The Hacker News 2026-09-05 Data from November 2019 to August 2021; CVE-2026-72898 in Metabase at CVSS 10.0; ShipMonk silent publicly; Holborn attribution to ShinyHunters; deletion assurances. Open source
- ShipMonk speaks. A public statement from ShipMonk naming other affected clients by the end of September would show the scope is wider than Trezor; continued silence would leave every ShipMonk customer guessing.2 The Hacker News 2026-09-05 Data from November 2019 to August 2021; CVE-2026-72898 in Metabase at CVSS 10.0; ShipMonk silent publicly; Holborn attribution to ShinyHunters; deletion assurances. Open source
- Anonymous Delivery ships on time. EU availability in September and US by year end, as promised, would show Trezor treating the fix as structural; a slip would suggest it was a press release.1 Trezor 2026-09-04 Timeline 10, 13, 14 August, 2 and 4 September; 13,689 in the first disclosure; about 67,000 additional US customers; fields exposed; no device or key exposure; written deletion assurances; Anonymous Delivery option planned. Open source
- Metabase patch adoption. Further breaches attributed to CVE-2026-72898 in the next quarter would show how many analytics deployments sit unpatched in front of customer databases.2 The Hacker News 2026-09-05 Data from November 2019 to August 2021; CVE-2026-72898 in Metabase at CVSS 10.0; ShipMonk silent publicly; Holborn attribution to ShinyHunters; deletion assurances. Open source
Trezor asked its vendor to delete the data and was told it had. The lesson for everyone else is that the only data a vendor cannot lose is the data it was never given.