Analysis
The authentication gap pattern reaches into crypto supply chains—not through the wallet, but through the fulfillment warehouse’s business intelligence tool.

On September 2, Trezor learned that a breach at its fulfillment partner ShipMonk was larger than initially reported. Another 67,000 U.S. customers had their personal data exposed—names, email addresses, phone numbers, shipping addresses, and order numbers—bringing the total to roughly 80,689. The affected orders span November 2019 to August 2021. Trezor’s devices were not compromised. The attack went through ShipMonk’s systems, specifically a Metabase instance that ShipMonk ran on the public internet.
The entry point was CVE-2026-72898, an unauthenticated SQL…







