Threat Intelligence Brief
Curated summary with source attribution
Source: bitbo.io
Threat Risk: Medium
Victim: Trezor hardware wallet customers
Incident: Data breach of third-party shipping provider ShipMonk exposing customer PII.
Impact: Exposure of names, emails, phone numbers, and addresses for nearly 14,000 users.
Attacker: Unidentified threat actors
Analysis: The breach originated at ShipMonk, a logistics provider, rather than Trezor’s internal systems. Attackers leveraged a critical SQL injection zero-day in Metabase to gain administrative access. This exposure of PII creates a high risk of sophisticated, targeted phishing campaigns aimed at stealing crypto recovery seeds.
Recommendations: Enable multi-factor authentication across all sensitive accounts.; Be skeptical of unsolicited communications claiming to be from Trezor or financial institutions.; Never share recovery seeds or private keys regardless of the sender’s perceived identity.
Source: Bitbo
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source
Latest Developments
Update — 2026-08-15 22:53 UTC
A data breach at third-party shipping provider ShipMonk exposed the personal information of nearly 14,000 Trezor customers. Exposure of names, addresses, and phone numbers links specific individuals to cryptocurrency holdings, increasing the risk of targeted attacks. The breach occurred at ShipMonk, a logistics provider, rather than within Trezor’s own infrastructure, illustrating a critical supply chain vulnerability. By linking real-world identities and home addresses to hardware wallet ownership, attackers have created a high-value target list. This exposure significantly elevates the risk of targeted phishing, social engineering, and potential physical extortion.
Corroborating source: ground.news