Trezor Discloses Breach Exposing 67,000 U.S. Customer Records Through Third-Party Metabase Zero-Day

AI-generated NewsSnap summary based on source reporting.
Published: 2026-09-06
Category: technology
Source: Rescana

Cryptocurrency hardware wallet provider Trezor has disclosed a breach at its logistics partner, ShipMonk, which exposed sensitive order data for approximately 67,000 U.S. customers. The incident was caused by the exploitation of a critical zero-day SQL injection vulnerability (CVE-2026-72898) in the Metabase analytics platform used by ShipMonk. No wallet seeds, private keys, or funds were compromised, but exposed data includes names, email addresses, phone numbers, and shipping addresses, increasing phishing and physical targeting risks.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai