Skip to main content
Sign in

ShipMonk

avoid.net/shipmonk28/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

ShipMonk is a Fort Lauderdale-based third-party logistics and fulfillment provider founded in 2014 that serves e-commerce brands including crypto hardware wallet manufacturer Trezor. In August 2026, ShipMonk disclosed that an unauthorized party had exploited a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform deployed by ShipMonk, to access Trezor customer order data for at least 13,689 individuals. The exposed records — which include home shipping addresses, phone numbers, and email addresses of confirmed hardware wallet purchasers — carry elevated risk in a crypto context because they combine verified device ownership with physical location data.

Have evidence about ShipMonk?

Timeline(8 events)

2026-05-10

Start of the breach window: orders placed from this date onward are within scope of the data accessed by the unauthorized party.

Trezor official blog

2026-08-03

Metabase zero-day vulnerability reportedly detected; ShinyHunters later identified as having exploited the flaw across multiple organizations.

DigitalShield / Escudo Digital

2026-08-06

Metabase publicly discloses the critical SQL injection zero-day (CVE-2026-72898, CVSS 10.0) and releases patches. Metabase notifies ShipMonk that an unauthorized party exploited the vulnerability to access customer data.

Help Net Security; Trezor official blog

2026-08-08

End of the breach window: the last order date for which customer data was accessible to the unauthorized party.

Trezor official blog

2026-08-10

ShipMonk notifies Trezor of the unauthorized access to customer order data.

Protos; CoinDesk

2026-08-13

Trezor publicly discloses the breach, notifies 13,689 affected customers by email, and confirms ShipMonk as the source. Trezor states its own infrastructure and devices were not compromised.

CoinDesk; BleepingComputer; SecurityWeek

2026-08-13

ShinyHunters lists Metabase on its dark-web leak site, claiming responsibility for the attack on the analytics platform.

SecurityWeek; Cybernews

2026-08-14

ShipMonk has not issued a public statement acknowledging the breach. No regulatory actions, lawsuits, or criminal charges publicly reported as of this date.

SecurityWeek
Provenance & Audit Trail

Decision Log

  • #1publish⛓ pending8/14/2026, 5:05:18 PM
    hash: 8ZPp3R4gBExSVerid28HdmBG7ti6MFq2cobuJ4d9Uu3H

0 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/14/2026, 5:05:07 PM

last updated: 8/14/2026, 5:05:18 PM

avoid.net — verified advice for a post-truth world