Trezor Faces 80K+ Customer Data Breach in Summer of Third-Party Hacks

Share

The summer of 2026 will be remembered as a difficult period for Trezor, the legendary hardware wallet manufacturer. Two distinct data breaches involving third-party partners exposed the personal information of more than 80,000 customers. An in-depth look at a supply chain attack with far-reaching consequences for the crypto ecosystem.

🔑 Key Takeaways

  • Over 80,000 Trezor customers affected by the ShipMonk breach, including 67,000 additional US customers revealed in September
  • A zero-day vulnerability CVE-2026-72898 (CVSS 10.0) in Metabase exploited by the ShinyHunters group
  • 347,000 newsletter subscribers compromised through email partner Brevo
  • Sophisticated phishing campaigns using fake security alerts about an STM32 vulnerability
  • Trezor confirms that private keys and funds remain secure on devices

The ShipMonk Breach: A Zero-Day Vulnerability at the Root

The first incident was reported to Trezor on August 10, 2026. The company issued its public statement three days later, on August 13. Attackers gained unauthorized access to ShipMonk systems on August 8, exploiting a zero-day vulnerability in Metabase, an analytics platform used by the logistics company. This flaw, cataloged as CVE-2026-72898, is an SQL injection in the /reset_password endpoint of Metabase, rated 10.0 on the CVSS scale. The extortion group ShinyHunters is behind this intrusion.

During the initial announcement, Trezor reported 13,689 affected customers. Among them, 11,742 had their full names, email addresses, phone numbers, and shipping addresses exposed. The remaining 1,947 customers had more limited exposure, with only their name, city, and email address. The affected order window ran from May 10 to August 8, 2026, corresponding to Trezor’s 90-day data retention policy. Affected customers were located in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.

A month later, in September 2026, Trezor revealed that the actual number of affected US customers was significantly higher. According to The Hacker News, 67,000 additional US customers were affected by the same ShipMonk breach, bringing the total to over 80,000 customers. The exposed data for these customers included names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021.

« The Trezor breach results from a supply chain attack starting with a zero-day vulnerability. By finding and exploiting the SQL injection flaw in Metabase, attackers were able to compromise several of its clients, stealing sensitive data and extorting the organization. »

Halborn, blockchain security firm

Contradictory Responses from ShipMonk

Trezor stated that it had repeatedly requested and received written assurances from ShipMonk confirming data deletion, in accordance with their contract and data policy. The company expressed disappointment that, despite these confirmations, data had not been deleted from ShipMonk’s systems. A Trezor spokesperson stated: « After 90 days, we delete or anonymize all customer data related to a purchase on our Trezor eShop. We chose 90 days because it is the shortest window that still covers the entire order lifecycle: delivery, returns, and any refund or replacement. After that, we have no reason to retain your address or phone number. »

The Brevo Incident and Phishing Campaigns

Shortly after, a second incident was added to the list. Brevo, Trezor’s third-party partner for email sending, was hacked. According to Protos, approximately 347,000 Trezor newsletter subscribers were affected. Trezor clarified that « the Brevo system contains no passwords, no wallet data, or any other personal information. » Attackers were able to access Trezor’s email domain, which has since been deactivated. Trezor launched an investigation.

Scammers used the compromised data to send phishing emails to subscribers, warning them of a « Critical Security Alert: STM32 Entropy Vulnerability » and attempting to get them to disclose their backup seed phrases. This social engineering technique exploits users’ trust in official Trezor communications.

IncidentDateCustomers AffectedData Exposed
ShipMonkAugust 202680,000+Names, emails, phones, addresses
BrevoSeptember 2026347,000Email addresses (newsletter)

Brevo is also the email provider for other crypto firms, including BitBox, CoinTracking, Peach Bitcoin, and Blocktrainer, all of which warned their users to be wary of phishing emails. BitBox reported phishing attempts citing a microcontroller entropy bug, while CoinTracking saw attempts using a fabricated breach to deceive users.

Context: Ledger, Coinkite, and Industry Precedents

Despite these two incidents involving third-party partners, Trezor was keen to reassure users: « What has not happened in 12 years is that a Trezor device or Trezor Suite exposes someone’s keys or funds. That is the part we control end-to-end, and that is the part that determines whether your BTC is secure. » The company added that it would reduce the amount of customer information held by its partners and review « vendor relationships and security requirements in light of this incident. »

As context, Ledger, Trezor’s main competitor, suffered a 2020 breach of its e-commerce database that exposed approximately one million email addresses and shipping data for some 270,000 customers. This incident led to years of phishing campaigns and several documented physical robberies of Ledger customers. The same period saw exploitation of a firmware vulnerability on Coinkite’s Coldcard wallets, with an estimated $116 million in bitcoin stolen according to TRM Labs.

« This is not a good month for hardware wallets. »

Changpeng Zhao, co-founder of Binance, on X

No significant bitcoin price movement was observed in response to these breaches. Bitcoin traded in a range of $60,000 to $65,000 for most of August 2026, illustrating the market’s resilience to security incidents affecting ecosystem players.


Conclusion and Outlook

These incidents highlight the inherent risks of supply chain attacks in the crypto ecosystem. While Trezor successfully preserved the integrity of its devices and the security of its users’ funds, the multiplication of breaches at its partners raises questions about due diligence regarding third-party security. The decision to reduce customer data held by partners is a step in the right direction, but the industry will need to collectively strengthen its security standards to prevent such incidents from recurring. Users are encouraged to remain vigilant against suspicious emails and never share their seed phrases, regardless of the pretext given.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice in any way. Do your own research (DYOR) before making any decisions.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles