Wire · technology
Trezor's Supply Chain Cracked Through ShipMonk's Unpatched Metabase
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 7 September 2026 · Fusion42 review
A critical unauthenticated SQL injection vulnerability in ShipMonk's publicly exposed Metabase instance allowed attackers to access and steal personal data of approximately 80,689 Trezor crypto hardware customers, despite contractual assurances for data deletion.
This Wire brief sits within Fusion42's coverage of Cybersecurity, and 3 sources have reported it between 5 Sep 2026 and 7 Sep 2026.
◆ ◆ The Wire takeaway
Unauthenticated internet-facing management tools now represent the weakest link in your supply chain security. You need to demand proof beyond contracts that operational tech is fully patched and access-restricted or risk your customers’ data and trust being compromised.
◆ Coverage
3 sources · first reported 5 Sep 2026 · latest 7 Sep 2026
◆ Related on Wire
◆ Topics