Security & Risk5 minNewsroom

Trezor Raises ShipMonk Leak to Over 80,000 Customers and Exposes Data Custody Chain

Corredor de galpão logístico ao entardecer com pallets de caixas e um funcionário passando por um terminal luminoso na parede.

Trezor confirms that ShipMonk retained orders it claimed to have deleted; a flaw in Metabase (CVE-2026-72898) opened an additional 67,000 records, bringing the total to over 80,000.

Trezor confirmed last week that the leak at its logistics operator ShipMonk involves not only the customers already notified in August but also an additional 67,000 buyers in the United States, raising the known total to over 80,000 exposed records. The Czech hardware wallet company states it received communication from ShipMonk on September 2 and published the new notice to customers on September 4. The supplementary dataset covers orders processed between November 2019 and August 2021, during a previous partnership that Trezor believed to be concluded.


Metabase Became the Entry Point


The breach traces back to the exploitation of a zero-day vulnerability in Metabase, an open-source business intelligence platform used by ShipMonk in a self-hosted instance. The flaw, cataloged as CVE-2026-72898, is an unauthenticated SQL injection with a CVSS score of 10.0, allowing the attacker to query the entire product database without credentials. ShipMonk reported the unauthorized access on August 10; Trezor issued its first communication on August 13, mentioning 13,689 affected customers.


The same vulnerability affects another corporate victim from the same operation, the cryptocurrency broker Bits of Gold, suggesting that ShipMonk operated a single Metabase environment shared among customer accounts. This detail matters for the enterprise buyer: when the logistics SaaS centralizes order analysis for multiple brands in a single instance, a flaw in the BI layer exposes all at once, even if the brands have no commercial relationship with each other.


There was no compromise of Trezor's physical wallets, nor of the customers' seed phrases, both designed to be isolated outside the logistics flow. The exfiltrated data is operational in nature: names, emails, phone numbers, delivery addresses, and order numbers from the period when ShipMonk was shipping products for Trezor.


The Critical Point is the Deletion Promise


Trezor claims it repeatedly requested ShipMonk to delete the data upon the end of their partnership and received written confirmation that the purge had occurred. The files remained in the database. This clause, common in data processing contracts under GDPR and LGPD, was violated on two fronts: the contractual duty of destruction and the duty of honesty regarding compliance. The vendor's word, without technical verification, became worth less than the records it claimed to have deleted.


The case reopens a discussion that data executives have been postponing: how to audit compliance with deletion clauses in vendors who operate SaaS or physical services, without halting operations. Few contracts provide for technical scanning post-termination, and even fewer provide for the custody of corroborative logs by the controller. The standard model remains trust in the counterpart's statement, now officially insufficient for devices that also suffer from so-called wrench attacks: physical assaults against crypto asset owners identified from residential addresses in logistics databases.


Geographical Scope and Next Target


ShipMonk operates distribution centers for clients in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. This broadens the scope of what other brands that hired the same vendor may need to communicate to their own users, with distinct regulatory implications in each jurisdiction. The ANPD, in Brazil, requires notification to data subjects in incidents that pose significant risk, and European regulators may frame non-compliance within the deletion obligation of Article 17 of the GDPR, applicable to the contracted processor.


For the CISO of any company dispatching goods through a third-party logistics operator, three immediate considerations arise. First, determine whether the vendor operates self-hosted Metabase instances and, if so, demand proof of the correction of CVE-2026-72898 before the next business cycle. Second, review retention and deletion clauses in existing contracts, adjusting the window and verification mechanics. Third, consider cryptographic rotation of order identifiers and the use of intermediate addresses for sensitive products, a practice that Trezor itself has indicated it is evaluating for new cycles, which removes from the vendor the capacity to retain useful information independently.


The underlying question is not technical. It is about contractual governance: when a custody chain relies on what the vendor claims to have done, the buyer assumes the full risk of deceit. The Trezor case compels the corporate logistics market to discuss whether the next generation of contracts requires, in addition to the promise, some equivalent of a cryptographic receipt to prove that the data has indeed left the database.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk