Skip to content
>_ITDITDWeb Security Platform

Security Guides

Metabase vulnerability breaches (Trezor 80,689 customers and others): what leaked, and what affected people and analytics-tool operators should do

A Metabase flaw exploited before its patch exposed customer data at Trezor (80,689 names and addresses), Framework, n8n and others. What to do now.

Published 2026-10-03 Updated 2026-10-03 Last verified 2026-10-03 12 min read

For: people who ordered a Trezor hardware wallet; users of Framework, n8n, Tally, Kilo Code and Privy; and anyone who runs Metabase or a similar analytics tool. This article is based on each organization's official disclosures and news reporting and does not cover attack techniques. The technical details of the flaw and how to fix it are in our CVE-2026-72898 alert.

Are you affected? Quick reference

Only organizations that disclosed impact themselves are listed (in order of disclosure). "Not disclosed" means the organization has not given a number.

OrganizationDisclosedWhat leaked (per the organization)CountNot included
Framework (laptops)Aug 6 (customer notice)Names, email addresses, login IP addresses, billing and shipping addresses, phone numbers, company namesNot disclosedOrder and payment data
n8n (workflow automation)Aug 8Names and email addresses; five records included hashed passwords136 records—
Kilo Code (part of Anaconda)Aug 9For some users: names, email addresses, billing addresses, location data, Slack access tokens, partial or full promptsNot disclosed (some users)Payment card data
Privy (wallet infrastructure)AugustCustomer and end-user email addresses, some developer-set fieldsNot disclosedWallet infrastructure and authentication systems
Trezor (hardware wallets)Aug 13; scope expanded in SeptemberNames, email addresses, phone numbers, shipping addresses, order numbers80,689 customersWallets, private keys, backups, payment data

In addition, form builder Tally reportedly told users that email addresses and hashed passwords were taken from its analytics environment, and that forms and responses were unaffected because they were stored separately.

Hashing means converting a password into a form that cannot be turned back into the original. It cannot be read directly, but short or reused passwords can sometimes be guessed, so change yours if you were notified.

What to do today

1

Trezor customers: never enter your backup (recovery seed), for any reason

The recovery seed is the 12 to 24 words that restore your wallet. Anyone who has them can move your funds without the device.

Trezor asks customers to never enter the backup on a website or share it with anyone. That holds whether the message claims a vulnerability, an account check or a move to a new app, and whether it arrives by email, text, phone or letter.

2

Trezor customers: assume your home address is known, and watch your mail and doorstep

What leaked here is shipping addresses. Trezor itself says this could expose affected people to physical security risks (danger that comes from someone knowing where you live).

If you receive a letter claiming to be from Trezor, or a parcel you did not order (such as a "replacement device"), do not follow the instructions inside; contact Trezor through its official site yourself. Not discussing how much crypto you hold on social media matters more than before.

3

Trezor customers: rethink delivery and contact details for future orders

For future orders, Trezor suggests considering an anonymous email address, paying in cryptocurrency and using a P.O. box. A parcel locker or pickup point also keeps your home address off the shipping label.

4

If n8n, Tally or another service notified you: change your password and stop reusing it

n8n asks notified users to reset their password as soon as possible. If you use the same password elsewhere, change it there too. A password manager is the practical way to keep them separate.

5

Kilo Code users: check your Slack connection and sessions

Kilo Code says Slack access tokens (strings that let an app act in Slack without logging in) were included for some users of its Slack integration. Review the app's permission in Slack, and look for sessions you do not recognize in your Kilo account. Since August 18, Kilo has offered an export feature that lets you download the data of yours that was accessed.

6

Everyone: do not open links in messages claiming to be from these companies

A name, email address and phone number together make convincing messages possible. Do not open links in messages you receive; check by opening the official site or app yourself (see what phishing is).

A separate incident: fake email to Trezor newsletter subscribers (September 2026)

Trezor says that on September 9, 2026, the email service it uses to send its newsletter was breached and a fake security warning was sent from Trezor's account to about 347,000 subscriber addresses.

The email falsely claimed a flaw in a wallet component and pushed readers to an app that asked for their backup. Trezor says it took the domain down in about 20 minutes, but about 2,500 people had clicked the link before then. This is separate from the Metabase incident, and it differs in that the email came from the real sender. Even from a genuine sender, any request for your backup is fake.

What happened (from the organizations' disclosures)

Metabase is a BI (business intelligence) tool that connects to an organization's databases to build charts and reports. It can be run by the organization itself (self-hosted) or used as a cloud service run by Metabase.

According to Metabase, on August 3 a cloud customer reported an API key created outside working hours; investigating it led to a previously unknown vulnerability. Metabase says fewer than 3% of its cloud customers, plus some internet-reachable self-hosted instances, were compromised before the fix.

  1. August 2-3, 2026

    Kilo Code (about four hours on August 2) and n8n, Framework and Tally (August 3) say unauthorized access occurred in their analytics environments.
  2. August 6

    Metabase releases fixed versions, says the flaw had been exploited before the fix, and notifies affected customers. Framework sends its customer notice.
  3. August 8-9

    n8n and Kilo Code disclose their impact.
  4. August 11

    US CISA adds the flaw to its catalog of actively exploited vulnerabilities (KEV).
  5. August 13

    Trezor discloses that 13,689 customers' data leaked from its logistics partner's analytics environment.
  6. August 27

    Metabase publishes an account of what happened and its hardening plans.
  7. September 2

    Trezor is told by the partner that US order data from 2019-2021 for about 67,000 customers was also included, and later updates its disclosure (80,689 in total).
80,689
Trezor: customers whose names, addresses and phone numbers leaked
136
n8n: records accessed (five with hashed passwords)
<3%
Metabase: share of cloud customers compromised before the fix
Not included
All: payment data such as credit cards
Trezor (disclosed August 13, 2026; updated in September)
Route
The analytics environment of the logistics partner that stores and ships Trezor's products. According to reporting, the partner told its customers that a vulnerability in Metabase's software was exploited
Affected (2026)
Orders shipped from the US, UK, Sweden, Colombia, Brazil, Italy and Portugal between May 10 and August 8. 11,742 customers with all fields; 1,947 with name, city and email only
Affected (older)
About 67,000 US orders from November 2019 to August 2021, all fields
Data
Name, email address, phone number, shipping address, order number
Not affected
Trezor's systems, hardware wallets, private keys, wallet backups, payment data
Older data
Trezor says it repeatedly asked the partner to delete the data under their contract and data policy and received written confirmation that it had, but the data had not been deleted
Notification
Email to affected customers from notification@trezor.io

For people who run analytics tools

Upgrading, revoking sessions and rotating connected-database credentials are covered step by step in our CVE-2026-72898 alert. Here we cover one more point the victims' cases show: cloud customers were compromised before they could do anything themselves. At that point, the only thing that limited the damage was what the tool had been allowed to read.

What widened the damage (per the disclosures)

  • The analytics tool could read address and phone columns
  • Years-old order data that was supposed to be deleted remained at a partner
  • Self-hosted instances reachable from the internet were compromised (per Metabase)

What limited it (per the disclosures)

  • Tally stored forms and responses in a separate place
  • Privy kept its wallet infrastructure separate from the analytics environment
  • Framework said it would restrict access to only the columns analysis needs
1

List the columns your analytics tool's database user can read

Start here. In the Metabase admin screens (or your tool's equivalent), list every connected database, then write down which tables and columns each connection user may read (in PostgreSQL, information_schema.role_table_grants and information_schema.column_privileges show this).

2

Reports rarely need addresses, phone numbers or email addresses

Sales and usage reports usually need dates, amounts, products, a coarse region and a customer ID. Create views that contain only the needed columns (a view is a virtual table that exposes part of a table), and grant the connection user read access to those views only. The customer ID can be a substitute value rather than the real one (pseudonymization).

3

Check that data you gave partners is really deleted

In Trezor's case, years-old order data remained at a partner. A partner's analytics environment is one more place your data lives. Do not stop at a deletion clause in the contract: agree what is deleted, how, and how you will verify it, and check at the end of the contract and periodically.

4

Keep self-hosted analytics tools off the open internet

Only your own staff should use an analytics tool. Use a VPN, source-IP restrictions or an internal-only network so that the login page itself is not visible from outside. This flaw sat in code that runs before login, so strong passwords and multi-factor authentication did not stop it (see defending against VPN device vulnerabilities, and password reset design flaws for why reset flows are a common target).

5

Decide in advance how many days you have to fix a vulnerability

Decide ahead of time where vulnerability information arrives, how many days you have to fix each severity, and who makes the call. Internal tools such as analytics often have no clear owner for updates. Start from a list of the tools you run and who owns each (security inventory checklist, CVE remediation playbook).

This site's view: analytics data tends to become a copy of production

Analytics tools are treated as "just for looking" and run with less care than the production database. But once connected, they can read the same data. In this wave, every organization listed lost data from its analytics environment, not from its main service.

Few reports need a home address. A column the tool cannot read cannot leak. This is also the measure that still works when you cannot patch in time — which was exactly the cloud customers' situation.

Sources (public records)

The facts in this article are based on the following public information. We do not speculate about undisclosed intrusion methods or causes.

  • Metabase, "Security update available for Metabase" (August 6, 2026) — metabase.com
  • Metabase, "August 2026 Security Vulnerability: What happened?" (August 27, 2026) — metabase.com
  • Trezor, "Recent customer data exposed in shipping provider incident" (August 13, 2026; updated September) — trezor.io
  • Trezor, notice on the security incident at its newsletter email provider (September 2026) — trezor.io
  • n8n, "Metabase security incident update" (August 8, 2026; updated August 11) — blog.n8n.io
  • Anaconda, "Metabase Incident Impacting Kilo Code Customer Data" (August 2026) — anaconda.com
  • Privy, "Post-mortem on August 6, 2026 Metabase security incident" — privy.io
  • Reporting: BleepingComputer on the Framework and Tally notices — bleepingcomputer.com / on Trezor's expanded scope and the partner's statement — bleepingcomputer.com
  • US CISA, "Known Exploited Vulnerabilities Catalog" (CVE-2026-72898, added August 11, 2026) — cisa.gov

Update history

2026-10-03: First version, based on official disclosures by Metabase, Trezor, n8n, Anaconda (Kilo Code) and Privy, and on reporting about the Framework and Tally notices. We will update it if more organizations disclose impact.

FAQ

QWhich companies were hit through the Metabase vulnerability, and what leaked?
A

According to their own disclosures: Trezor lost 80,689 customers' names, addresses, phone numbers, email addresses and order numbers from a logistics partner's environment; Framework, customers' names, email addresses, login IP addresses, billing and shipping addresses and phone numbers; n8n, 136 records of names and email addresses (five including hashed passwords); Kilo Code (part of Anaconda), some users' names, email addresses, billing addresses, Slack access tokens and parts of prompts; and Privy, customer and end-user email addresses. All say payment data such as credit cards was not included.

QAre the funds in my Trezor wallet at risk?
A

Trezor says its own systems were not breached and that hardware wallets, private keys and wallet backups were not affected. The real risk is being tricked, by a convincing message that uses your leaked name, address and phone number, into entering your wallet backup (recovery seed). Trezor asks customers never to enter the backup on a website or share it with anyone.

QWhich Trezor customers are affected?
A

Trezor says it covers 13,689 customers who received orders shipped from the US, UK, Sweden, Colombia, Brazil, Italy and Portugal between May 10 and August 8, 2026, and about 67,000 US customers who ordered between November 2019 and August 2021. Affected customers were notified by email from notification@trezor.io.

QI got a 'security alert' email from Trezor. Is it related?
A

That is a separate incident. Trezor says that on September 9, 2026, the email service it uses for newsletters was breached and a fake security warning was sent from Trezor's account to about 347,000 newsletter subscribers. The link led to an app that asked for the wallet backup. Trezor says it took the domain down in about 20 minutes, but the addresses could be used for more phishing later.

QWe run Metabase. What should we do?
A

The technical response — fixed versions, the interim workaround, and revoking sessions and rotating connected-database credentials after upgrading — is in this site's alert on CVE-2026-72898. This article covers what the victims' cases add: reviewing what data your analytics tool is allowed to read.