This outlet covered CVE-2026-72898, the maximum-severity Metabase SQL injection flaw, on 11 August when Framework and Tally confirmed customer data had been exposed through it. Three days on, the blast radius has reached a company whose customers have a very specific reason to worry about their home address leaking: a hardware crypto wallet maker.
The same vulnerability, a different route in
Trezor, the hardware wallet brand made by Prague-based SatoshiLabs, does not appear to have been breached directly. On 10 August, ShipMonk, one of Trezor’s shipping and fulfilment providers, told Trezor it had detected unauthorised access to systems holding customer order data, with the intrusion window running from 10 May to 8 August. ShipMonk has told affected customers the access point was a vulnerability in Metabase, the third-party analytics platform ShipMonk runs internally, the same CVE-2026-72898 unauthenticated SQL injection in the /api/session/reset_password endpoint that we described three days ago as handing attackers admin access to every database a Metabase instance touches.
What actually leaked, and who it hits
Trezor disclosed on 13 August that 13,689 customers were affected: 11,742 with full exposure of name, email address, phone number and shipping address, and a further 1,947 with partial exposure of name, city and email. The company named the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal as affected countries, covering orders placed between 10 May and 8 August 2026. For most e-commerce breaches, a leaked shipping address is an annoyance. For a hardware wallet customer, it is a physical security problem: it confirms to anyone with the data exactly which addresses hold a device capable of controlling cryptocurrency, a targeting list that has previously been used for burglary and coercion attempts against known holders.
A deadline that lands today
CISA added CVE-2026-72898 to its Known Exploited Vulnerabilities catalog on 11 August, the same day this outlet’s original coverage ran, with a remediation deadline for US federal agencies of today, 14 August. Trezor and ShipMonk are private companies outside that mandate, but the timeline is instructive: the vulnerability was public, rated a perfect 10.0, and already confirmed exploited against Framework and Tally before ShipMonk’s exposure window even closed. Separately, workflow automation platform n8n disclosed on 8 August that the same flaw had exposed 136 of its own customer records, another organisation that had no direct relationship with Trezor’s customers but ended up in the same incident chain.
Vendor risk doesn’t stop at your own patch cadence
Trezor’s own systems may be entirely sound; the exposure came through a fulfilment partner running analytics software Trezor almost certainly never evaluated. That is the uncomfortable reality of modern vendor risk: your GDPR Article 28 processor agreements and your own patch cadence do not protect customer data sitting inside a sub-processor’s BI tool. Any organisation that shares customer PII with a shipping, fulfilment or analytics vendor now has a concrete reason to ask that vendor, this week, whether it runs Metabase and whether it has confirmed it is on 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, 0.63.5 or later.
If your organisation needs help mapping which vendors and sub-processors hold your customer data, building the questions to ask them after a disclosure like this one, or assessing your own exposure to CVE-2026-72898 directly, contact Excello Digital. We help European organisations turn a supply chain breach notice into a concrete list of what to check next, not just a headline to worry about.
