Skip to content

Coins

Trezor Email Provider Breached Amid Spread of Fake Wallet Security Alert

Trezor Warns Customers of Phishing Campaign Following Third-Party Email Provider Breach Hardware wallet manufacturer Trezor has alerted users to a phishing campaign targeting its customers after attackers compromised a third-party...

Trezor Warns Customers of Phishing Campaign Following Third-Party Email Provider Breach

Hardware wallet manufacturer Trezor has alerted users to a phishing campaign targeting its customers after attackers compromised a third-party email provider. The fraudulent message mimics a critical security advisory, attempting to lure recipients into revealing sensitive wallet information.

Fake Security Alert Mimics Legitimate Warning

The phishing email carries the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” The message falsely claims a major security risk affects Trezor hardware wallets, creating urgency designed to pressure users into clicking malicious links. Those links direct victims to a website requesting confidential wallet details, including recovery seeds.

Trezor confirmed the email is fraudulent in a public statement:

The email…is not coming from us, and it’s a phishing attempt.

Attackers Exploited Legitimate Domain

The company has taken down the domain used in the campaign and is investigating how threat actors gained access. Because the emails originated from a genuine domain, they bypassed typical sender-verification checks, making the deception more convincing even for security-conscious users who routinely inspect sender addresses.

Trezor has not disclosed the identity of the compromised email provider, the number of customers who received the malicious message, or whether any customer data was accessed during the breach. The firm also reports no cryptocurrency losses linked to this specific campaign.

Separate Incident Involving Shipping Provider ShipMonk

This email provider breach follows an earlier security incident involving Trezor’s shipping partner, ShipMonk. That breach exposed names, email addresses, phone numbers, and delivery addresses. Trezor later disclosed an additional 67,000 U.S. customers were affected.

The company has not connected the two incidents or suggested the same threat actors are responsible for both.

Recommended Actions for Affected Users

  • Do not click any links in the suspicious email.
  • Delete the message immediately.
  • Never enter your wallet recovery seed on any website or share it with anyone.

Trezor continues to investigate the email provider breach and has pledged further updates as the investigation progresses.

Evan Mercer

Penulis

Evan Mercer covers coins, digital assets and the market stories shaping everyday conversations about money. His work focuses on accessible explanations, useful context and the signals behind sudden moves.