// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
Breach Record

Trezor

DISCLOSED 2026-08-23 · UNPATCHED CVE · 53,487 RECORDS EXPOSED

Trezor disclosed a data breach affecting 53,487 customers, exposing names, emails, and addresses. The breach originated from its shipping provider ShipMonk, which was targeted by ShinyHunters using a SQL injection in Metabase. SafePal was also affected, but the text focuses on Trezor's breach.

The record

What we know

Disclosed
2026-08-23
Attack vector
Unpatched Cve
Sector
cryptocurrency hardware wallets
Records exposed
53,487
Data classes exposed
namesemailsaddresses
Sources

Cited reporting

Similar vector · recent

Other unpatched cve breaches on file

This page is the permanent ColdRecon entry for the Trezor disclosure. It updates if new public reporting emerges. All tracked breaches →

Trezor just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →