Trezor's email provider was breached; attackers sent fake security alerts falsely claiming hardware flaws could expose recovery phrases.
Security & Exploits ·
Trezor's third-party email provider was compromised, enabling attackers to dispatch a phishing message masquerading as an urgent security notice. The fraudulent email alleged that STM32 microcontrollers embedded in Trezor devices contained a critical flaw affecting approximately one in four units, potentially undermining the randomness of recovery phrases. Trezor publicly flagged the campaign as non-authentic and advised users to disregard any links, though the message had already circulated to customers hours before the company's warning.
Security researchers indicated the breach may span multiple hardware wallet providers. Casa Chief Security Officer Jameson Lopp noted similar malicious emails targeting BitBox users, suggesting a compromised marketing or email infrastructure provider rather than isolated account takeovers. Both campaigns employed identical tactics: false claims about defective random-number generators paired with pressure to click suspicious links, though neither Trezor nor BitBox had issued legitimate security advisories matching the attack's claims.
The incident follows a shipping breach at Trezor's logistics partner ShipMonk weeks earlier, which exposed personal information for approximately 80,689 users including names, addresses, and email addresses—data now potentially leveraged for refined phishing operations. What remains unclear is the full scope of affected email providers and how many users clicked links or completed malicious redirects.