Trezor Confirms 13,689 Customer Records Exposed via ShipMonk Metabase SQL Injection
A third-party logistics provider’s Metabase deployment leaked Trezor customer PII after exploitation of a disclosed SQL injection flaw. Technical evidence points to ShinyHunters activity, yet ShipMonk has issued no statement. The incident highlights persistent supply-chain data retention risks for hardware wallet vendors despite their own 90-day limits.
Trezor stated the breach occurred entirely at fulfillment partner ShipMonk after notification on 10 August. The data set matched exactly the fields Trezor transmitted for order shipping under its 90-day retention policy. No device keys, seed phrases or Trezor backend systems were accessed. ShipMonk has not published an incident report or confirmed the vector publicly. Technical details released by Metabase on 1 August describe a pre-authentication SQL injection in the embedded analytics service that permitted arbitrary query execution and data exfiltration. ShinyHunters posted a sample claiming origin from Metabase-hosted instances the same week. Procurement records show ShipMonk lists Metabase among its default analytics stack in multiple RFP responses. The pattern matches prior ShinyHunters operations against third-party SaaS tools used by logistics providers rather than direct targeting of crypto vendors. Supply-chain exposure of this type bypasses the hardware wallet vendor’s own security controls and creates targeted phishing lists with verified purchase timestamps. Affected users received notice to treat all inbound communications as potentially hostile; no further Trezor action has been disclosed. ShipMonk remains silent on scope beyond the Trezor subset and has not confirmed whether other clients were also hit.
ShinyHunters: At least two additional logistics clients using Metabase named in leaks within 45 days
Sources (2)
- [1]Trezor Customer Notice(https://trezor.io/support/a/data-breach-notice)
- [2]Metabase Security Advisory(https://www.metabase.com/blog/security-advisory)