Trezor warns of phishing campaign after email provider breach
Regulation & Gov ·
Trezor says a third-party email provider was compromised, allowing attackers to send phishing messages through its legitimate domain to users of the hardware wallet maker.
Trezor has flagged an email titled "Critical Security Alert: STM32 Entropy Vulnerability" as fraudulent, telling users the message did not originate from the company and urging recipients not to click any links inside it, according to wublockchain.xyz. The company has since taken down the domain used to distribute the message and is investigating how the attackers gained access to its legitimate infrastructure.
The phishing email falsely claimed that a hardware flaw in the device's STM32 chip could expose users' recovery phrases, a tactic corroborated by a separate report noting the fake alerts warned recipients that hardware defects put their seed phrases at risk, per decrypt.co. Because the emails were sent through channels tied to Trezor's own domain, recipients had limited means to distinguish the messages from genuine security notices, raising the risk that users might act on the fabricated vulnerability claim and expose their credentials or seed phrases by following embedded links.
Trezor is described as the second-largest hardware wallet maker, underscoring the potential reach of the breach given the size of its user base. The incident centers on a third-party email vendor rather than Trezor's core hardware or firmware, but the exploitation of a trusted domain to distribute phishing content illustrates how vendor-side security gaps can be leveraged against a company's customers even when its own products remain unaffected.
It remains unclear how the attackers obtained access to the email provider's systems, how many users received the phishing message, or whether any recovery phrases or funds were compromised as a result. Trezor's investigation into the breach's origin is ongoing, and the company has not yet detailed what remediation steps it will require from the third-party provider or how it will prevent similar domain misuse going forward.