
Work Here?
ShipMonk provides e-commerce order fulfillment as a 3PL, using a global warehouse network (US, Canada, Mexico, UK, and Europe) to store inventory closer to customers for faster shipping. It automates order processing through a platform that integrates with over 100 marketplaces and offers real-time tracking, plus inventory management tools to edit orders before shipment and view detailed logs. It differentiates itself with an agile, personalized fulfillment approach and broad platform integrations rather than traditional 3PL/4PL models, supported by its warehouse network and fast shipping options. The goal is to help e-commerce brands scale by delivering fast, reliable fulfillment and near-market inventory.
Industries
Industrial & Manufacturing
Enterprise Software
Company Size
1,001-5,000
Company Stage
Growth Equity (Venture Capital)
Total Funding
$365.1M
Headquarters
Fort Lauderdale, Florida
Founded
2014
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$365.1M
Above
Industry Average
Funded Over
4 Rounds
Professional Development Budget
Wave of crypto hardware wallet data breaches hits SafePal, Trezor, and Bits of Gold - Nearly 250,000 users exposed in weeks. A cluster of data breaches has swept across the cryptocurrency hardware wallet industry over the past several days, exposing personal information belonging to tens of thousands of customers at SafePal and Trezor - two of the most widely used hardware wallet manufacturers - while a separate incident at Israeli crypto broker Bits of Gold has potentially compromised data for another 200,000 users. None of the breaches exposed seed phrases, private keys, or funds directly, but security researchers warn the leaked personal information creates serious downstream risks for crypto holders, from targeted phishing to physical "wrench attacks." SafePal: Nearly 40,000 Customers Affected SafePal disclosed on August 16 that it had identified an authorization flaw in the order-tracking function of a plug-in connected to its customer order system. Under specific conditions, the flaw allowed unauthorized third parties to access order information belonging to other customers. The company said it remediated the vulnerability upon discovery and implemented additional security measures. According to SafePal's, the exposed data affects customers who placed orders between March 2, 2025, and April 11, 2026, and includes names, email addresses, shipping addresses, phone numbers, and purchase details. In total, SafePal confirmed the incident affects approximately 39,798 customers. All affected users were individually notified by email from [email protected] on August 16, with the subject line "[Important] Your SafePal Order Information Has Been Affected." SafePal was explicit that seed phrases, private keys, and wallet passwords were not exposed in the breach, meaning affected users do not need to move their assets solely because of this incident. However, the company warned that anyone who separately entered or shared their seed phrase or private key in response to a suspicious message should treat that wallet as compromised, create a new wallet using a trusted SafePal device or official app, and transfer remaining assets immediately. SafePal's core security guidance for affected users is straightforward: never share a seed phrase, private key, or password with anyone - including someone claiming to represent SafePal support, since the company says it will never request this information by phone, email, or any other channel. Users should avoid clicking links or scanning QR codes in unsolicited messages, manually type SafePal's web address rather than following links (the company noted it has previously taken down phishing sites that replaced the letter "l" in its domain with a capital "I"), and report any suspicious contact through SafePal's official channels rather than social media. Trezor: Breach Traced to Shipping Partner ShipMonk Just three days before SafePal's disclosure, Trezor its own data exposure incident on August 13, though the root cause differed meaningfully. According to Trezor's official blog post, the breach originated not from Trezor's own systems but from ShipMonk, one of the company's third-party shipping and fulfillment providers, which experienced a data breach exposing customer order information. Trezor stated plainly that its hardware devices remain secure and were not compromised in any way. The exposed data includes full names, shipping addresses, phone numbers, and email addresses tied to orders shipped between May 10 and August 8, 2026, specifically affecting customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor provided a precise breakdown of the incident's scope:" The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email)." The company attributed the relatively contained scale of the breach to its strict 90-day data storage policy - a retention limit it says it successfully negotiated with fulfillment partners as well, meaning older order data had already been deleted before the breach occurred. Customers uncertain whether they were affected were advised to check their inboxes for a notification from [email protected]. Trezor's Privacy Recommendations Going Forward In response to the incident, Trezor outlined several steps customers can take to reduce data exposure on future orders. The company recommended using an anonymous email address not linked to one's real identity when placing orders, and suggested paying with cryptocurrency rather than a credit card where possible - or using disposable digital cards for online purchases if crypto payment isn't an option. Trezor also suggested using a P.O. Box to limit address exposure, while noting that identification is typically still required for package collection and that postal services retain their own data records regardless. Trezor additionally teased an upcoming "Anonymous Delivery" feature, designed to let customers receive hardware wallets more privately through a dedicated checkout process, locker pickup options, neutral packaging, generic sender details, and automatic deletion of shipping identifiers following delivery. Bits of Gold: A Third Breach in Israel Adding to the pattern, Bits of Gold - Israel's largest regulated cryptocurrency broker - separately reported a potential data breach affecting up to 200,000 clients, though fewer technical details have been made public compared to the SafePal and Trezor incidents. The near-simultaneous timing of three separate crypto-industry data exposures within roughly the same week has amplified concern across the sector about the security practices of vendors and partners handling crypto customer data. Why These Breaches Matter Even Without Stolen Funds Security researchers have repeatedly emphasized that even when seed phrases and private keys remain untouched, breaches exposing names, addresses, and purchase details tied specifically to cryptocurrency hardware purchases carry outsized risk compared to typical e-commerce data leaks. A leaked customer list confirming that a specific person owns a hardware crypto wallet - and knows their home address - provides exactly the targeting information needed for sophisticated phishing campaigns, fraudulent "customer support" outreach, and, in more extreme cases, physical confrontation or coercion, sometimes referred to in the industry as "wrench attacks." Part of a Broader Pattern of Sensitive Data Exposure These crypto-specific incidents are unfolding against a backdrop of other major data breaches with similar targeting implications. In France, a leak reportedly exposed data belonging to 678,000 taxpayers, including income figures, addresses, and property details - information that, while not crypto-related, provides exactly the kind of financial profiling criminals use to identify and select wealthy targets for extortion or robbery, independent of whether victims hold cryptocurrency at all. What Affected Users Should Do Now For anyone who has purchased a hardware wallet from SafePal or Trezor, or who holds an account with Bits of Gold, security experts recommend treating any unexpected communication referencing a past purchase - by phone, email, text, or physical mail - with heightened suspicion. This includes unsolicited firmware update requests, refund offers, or "support" calls asking for seed phrases or private keys under any circumstance. Genuine hardware wallet companies do not request this information through outbound contact. Users should verify any communication through official company channels by manually navigating to the company's known website rather than clicking links, and report suspicious contact through the companies' dedicated reporting channels rather than social media, where scammers can more easily impersonate support staff.
Israeli crypto broker Bits of Gold discloses breach tied to third-party software attack. Bits of Gold, Israel's largest regulated cryptocurrency broker, has told customers that a breach of a vendor system may have exposed personal and financial data, part of a wider software-supply-chain attack hitting hundreds of companies worldwide. Bits of Gold, a Tel Aviv-based cryptocurrency broker holding financial services license 56716 from Israel's Capital Market, Insurance and Savings Authority, notified customers on Aug. 16 that unauthorized access had been found in a third-party system the company uses for customer support and data analysis. The company said it detected the intrusion several days before the notice, cut off the compromised system from its data sources, and alerted regulators. The breach traces back to a software vendor used by Bits of Gold, not a direct strike on the broker's own network. Bits of Gold said it was one of potentially hundreds of businesses worldwide caught up in the same attack on the software provider, and that available information does not indicate the company was deliberately singled out. The identity of the software vendor has not been made public. An initial internal review found that intruders may have reached names, national identification numbers, email addresses, phone numbers, IP addresses, bank account numbers and public cryptocurrency wallet addresses tied to customer accounts. Bits of Gold said digital holdings, account passwords, scanned identification documents, full card numbers and card security codes were not affected, noting that it does not store customers' private keys or complete card data. The company said it has so far found no sign that any of the exposed data has been used maliciously. How many customers were affected has not been established. Figures placing the number near 200,000 have spread through social media and crypto news outlets, but Bits of Gold has not confirmed that count. The notice sent to customers did not specify a number of affected records, and the company's website lists more than 300,000 total customers. No other Israeli firm had been identified as caught up in the same attack at the time of the disclosure. "Similar to other financial entities, the company will never ask you to provide a password, verification code, or private key, and will not ask you to transfer money or digital assets to another wallet," Bits of Gold said in its customer notice. The company urged customers not to hand over passwords, verification codes or private keys, and not to send money or crypto assets in response to unexpected contact. Bits of Gold said it has engaged a specialized cyber incident response firm to conduct a full review and that it continues to monitor its systems. It said its platform remains fully operational and that customers do not need to take any account action at this time. The disclosure follows a separate third-party breach in the crypto industry in which an incident at fulfillment company ShipMonk exposed personal data belonging to 13,689 customers of hardware wallet maker Trezor, raising similar phishing concerns across the sector. Bits of Gold has not disclosed the confirmed number of affected customers, the identity of the compromised software vendor, or whether the exposed data has been used for fraud. Those details remain outstanding as the investigation continues.
ShinyHunters breaches ShipMonk: 14,000 Trezor customers' data exposed. This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy Key points * " 14,000 Trezor customers had personal data exposed via a third-party shipping provider, leading to elevated phishing risk. * " ShipMonk's systems, specifically Metabase, were compromised via a SQL injection vulnerability exploited by ShinyHunters. * " Affected customers must be vigilant against phishing attempts; organizations should review third-party data sharing practices. Overview of the ShipMonk data breach. The personal information of approximately 14,000 Trezor hardware wallet customers has been compromised following a data breach at ShipMonk, Trezor's third-party shipping provider. The incident, which Trezor states did not affect its own systems or device security, involved an unauthorized actor accessing customer data shared for order fulfillment purposes. The breach impacts customers in several countries, including the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal, who placed orders between May 10 and August 8. The primary concern arising from this exposure is the potential for highly sophisticated phishing attempts targeting affected individuals, leveraging the stolen personal details. This event underscores the critical importance of third-party risk management and the cascading effects of supply chain vulnerabilities, even when core systems remain secure, according to SecurityWeek. Discover more Security Products & Services Dictionaries & Encyclopedias Technical details and attribution. The breach at ShipMonk, a fulfillment and logistics provider, reportedly stemmed from the exploitation of a SQL injection vulnerability in Metabase, a data analytics solution. While the specific CVE ID for this vulnerability was not disclosed in the source, it is described as a zero-day flaw that Metabase recently patched. The notorious extortion group ShinyHunters has claimed responsibility for an attack on Metabase and subsequently leaked data, which aligns with the timing and nature of this incident. The compromised data includes: * For 11,742 customers: Full names, phone numbers, email addresses, and shipping addresses. * For 1,947 customers: Names, cities, and email addresses. Trezor clarified that its strict 90-day data storage policy for shipping information, which it negotiated with fulfillment partners like ShipMonk, helped limit the overall scope of the breach. However, for the subset of customers with partial data exposure, older orders might also have been accessed. ShipMonk has not yet publicly acknowledged the incident, and it remains unclear how many other companies or individuals might have been affected by the Metabase compromise. Impact of ShinyHunters data breach. The primary impact of the ShinyHunters data breach on Trezor customers is a significantly elevated risk of targeted phishing, spear-phishing, and social engineering attacks. With access to full names, shipping addresses, email addresses, and phone numbers, malicious actors can craft highly convincing communications that appear legitimate. These attacks could aim to: * Trick users into divulging cryptocurrency wallet seed phrases or private keys. * Lure individuals into installing malware on their devices. * Coerce victims into performing unauthorized transactions. * Gain further personal information for identity theft. This incident highlights the pervasive risk associated with third-party vendors who handle sensitive customer data. Even when an organization like Trezor maintains stringent security for its core products and services, the security posture of its partners directly impacts customer trust and safety. Understanding the ShinyHunters data breach impact means recognizing the long-term threat of identity exploitation and financial fraud that can follow such disclosures. Actionable recommendations and mitigations. For affected Trezor customers: detecting sophisticated phishing attempts. Trezor has already notified affected customers and advised extreme caution. Individuals who placed orders with Trezor between May 10 and August 8 should be hyper-vigilant for any suspicious communications. * Email Verification: Carefully examine sender addresses, grammar, and spelling in emails. Be suspicious of unsolicited emails asking for personal information, especially anything related to your crypto wallet. * Link Scrutiny: Do not click on links in suspicious emails or messages. Instead, navigate directly to official websites by typing the URL. * Phone Call Awareness: Be wary of phone calls from individuals claiming to be from Trezor, ShipMonk, or financial institutions asking for personal or financial details. * Two-Factor Authentication (2FA): Ensure 2FA is enabled on all online accounts, particularly email, banking, and cryptocurrency exchanges, to add an extra layer of security. * Password Hygiene: Use unique, strong passwords for all accounts and consider a password manager. For organizations: mitigating third-party supply chain risks. This incident serves as a stark reminder for all organizations about the vulnerabilities inherent in the supply chain. Proactive measures are essential to how to protect against supply chain data breaches. * Vendor Security Assessments: Conduct thorough security audits and assessments of all third-party vendors who handle sensitive customer or corporate data. This includes reviewing their security policies, incident response plans, and data protection measures. * Data Minimization: Implement a policy of sharing only the absolute minimum data necessary with third parties. Trezor's 90-day data retention policy for shipping information is an example of a good practice for limiting exposure. * Contractual Obligations: Ensure vendor contracts include explicit clauses regarding data security, breach notification, and liability. * Continuous Monitoring: Establish mechanisms for continuous monitoring of third-party security postures and potential vulnerabilities in their systems. * Incident Response Planning: Develop and regularly test incident response plans that account for data breaches originating from third parties, ensuring clear communication channels and responsibilities. Addressing Metabase SQL injection vulnerabilities. While the specific vulnerability exploited in this case remains unnamed, the mention of a Metabase SQL injection vulnerability highlights a common attack vector. Organizations using Metabase or similar data analytics tools should ensure all software is kept up-to-date with the latest security patches. Regularly performing security audits, including penetration testing and code reviews, specifically for SQL injection flaws, is crucial. Employing Web Application Firewalls (WAFs) and parameterized queries can also help prevent such exploitation. Security teams should monitor logs for unusual database activity that could indicate attempted or successful SQL injection attacks.
Trezor data breach exposes 13,689 users, crypto wallets remain safe from attack. August 14, 2026 Key Takeaways: * Through a leak in the software of its shipping partner ShipMonk, Trezor disclosed private information related to approximately 13,689 users. * Names, home and work address, and phone numbers and e-mail addresses are exposed, increasing the risk of targeted phishing. * There has been no compromise of Trezor's systems or hardware wallets and wallet backups were not compromised. User Score Trezor has warned customers about a data breach at ShipMonk, a third-party logistics provider responsible for fulfilling some Trezor orders. While no crypto wallets or Trezor systems were breached, the leaked personal information could give scammers more convincing ways to target crypto holders. Table of contents. ShipMonk breach exposes customer information. On August 10, ShipMonk informed Trezor of a third party accessing systems that contained customer orders. Trezor stated that it is continuing to investigate. The company estimates that 11,742 customers had their names, email addresses, phone numbers and shipping addresses exposed. Another 1,947 customers may have had their names, city information and email addresses accessed. The affected orders initially covered customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal who received orders during the relevant period. Trezor claims it has a 90-day data retention policy which would mean that ShipMonk could only have historical data for 90 days. The company has since warned that the 1,947 partially exposed records could contain some that are older orders but is still confirming that detail with the logistics provider. Any customer who got an official e-mail notification from [email protected] should feel the information was leaked. Trezor stated that those who missed that email are unaffected. Crypto wallets and private keys were not compromised. The breach did not affect Trezor's internal systems, devices or wallet security. The main risk is targeted phishing. Even if the information is stolen, it may still be useful to criminals if it contains information that could help to make a scam appear real. A victim's true name, phone number or delivery address could be used to impersonate services such as Trezor, a cryptocurrency exchange; bank or other trusted service. They can send emails, make phone calls and even use physical mail to try to force users to disclose these sensitive details. Trezor's warning comes as it advises customers who are potentially impacted to take special care of messages that urge them to act quickly or disclose personal information. Above all, users must never enter their wallet backup or recovery seed into a website. According to Trezor, their customers will not have to reveal their wallet backup in order to access the legitimate support. Trezor pushes privacy options for future orders. The incident also led to Trezor emphasizing the various measures customers can take to minimize the tracking of personal information going into hardware wallet purchases. The company suggests to use an e-mail address not associated with a real name, if cryptography payments are possible, and if possible, a P.O. Box. Furthermore, Trezor is working on an Anonymous Delivery feature to mitigate exposure to shipping details, including locker picking up, neutral packaging, generic sender information and auto deletion of shipping identifiers upon delivery. Liam Turner DeFi Analyst & Writer Liam focuses on decentralized finance (DeFi), with a strong background in financial markets and technology. He started as a crypto trader, gaining firsthand experience in navigating volatile markets. His articles demystify DeFi protocols and provide readers with actionable investment insights. Liam's clear explanations have made him a trusted voice in the community.
Crypto hardware wallet Trezor discloses data breach affecting nearly 14,000 customers. Highlights * Trezor disclosed unauthorized access to customers data through one of its shipping provider. * The data breach includes personal information affecting 13.689 customers. * The hardware wallet maker assured that its systems and devices remain secure. Crypto hardware wallet maker Trezor has announced a data breach involving customers' personal information. The firm assured that its devices remain safe but warned that affected customers could experience an increase in phishing attempts. Trezor discloses customer data breach. In a blog post, the crypto hardware wallet maker announced that one of its shipping providers, ShipMonk, suffered a data breach that granted unauthorized access to systems containing customer data. "We're extremely sorry to inform our community that customer personal information, including full names, phone numbers, email addresses, and shipping addresses, has been accessed by an unauthorized actor during this breach," Trezor said. The wallet maker further disclosed that the data breach affects 11,742 customers with full exposure, including customers' names, email, phone number, and shipping address. Meanwhile, 1,947 customers had partial exposure, with the breach limited to their name, city, and email. Trezor also announced that the affected customers received their orders in the U.S., U.K., Sweden, Colombia, Brazil, Italy, or Portugal within the 90 days before 8 August 2026. "Affected customers were emailed today from [email protected]. No email means not affected," the firm said. The top crypto wallet provider also assured customers that there is no compromise in their systems and that its devices remain secure. However, it warned that affected customers could see an increase in phishing attempts, with scammers actively trying to use the leaked information to access customers' wallets. Move to curb A repeat of such incident. Trezor also disclosed that they are currently working on an Anonymous Delivery option, a move which could help avoid a repeat of such a shipping data breach. The firm aims to have this ready by September for the E.U. and by the end of the year for the U.S. "This gives you a safer way to order hardware wallets without linking the purchase to your home address or real-world identity," the wallet maker said. The option will enable users to use a nickname or label ID for their orders and select an automated parcel locker for pickup. They could also select unbranded packaging with a generic sender label. Trezor assured that the project is a top priority at the moment. It is worth noting that the incident follows the Coldcard hack, which again raised questions about crypto wallet security and the safety of self-custody. Galaxy Research estimates that users lost up to $116 million in Bitcoin from the Coldcard incident. Investment disclaimer: The content reflects the author's personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses. Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over its editorial content. BestChange Instant Currency Exchange at BestChange with Ease * Compare Rates Across 1000+ Exchanges * Access 250+ Cryptocurrencies & Pairs * Save Time with Real-Time Price Tracking * Trusted & Verified Exchange Listings Why Trust CoinGape * Latest * / * Trending
Find jobs on Simplify and start your career today
Industries
Industrial & Manufacturing
Enterprise Software
Company Size
1,001-5,000
Company Stage
Growth Equity (Venture Capital)
Total Funding
$365.1M
Headquarters
Fort Lauderdale, Florida
Founded
2014
Find jobs on Simplify and start your career today