Trezor's third-party email provider breached
Security & Exploits ·
Phishing emails impersonating Trezor's official domain circulated after a third-party email vendor was compromised, prompting the company to shut the domain down.
Trezor said in a statement that its third-party e-mail provider had been breached, and that an email titled "Critical Security Alert: STM32 Entropy Vulnerability" did not originate from the company despite appearing to come from its legitimate domain, according to a post on X. The company described the message as a phishing attempt and told users not to click any links contained in it. Trezor added that it had taken down the affected domain and was investigating how the breach occurred, including how attackers gained access to its legitimate infrastructure.
The phishing emails were crafted to look convincing, exploiting the fact that they were sent through Trezor's own domain rather than a spoofed lookalike, which made them harder to distinguish from genuine company communications. The fake "STM32 Entropy Vulnerability" alert played on the kind of hardware-security language users might expect from a legitimate wallet manufacturer, increasing the risk that recipients would click through without suspicion.
The incident has been corroborated across multiple reports, with coverage describing the same sequence: a breach at Trezor's email provider, followed by phishing emails reaching customers from the company's real domain, and Trezor's decision to take the domain offline while it investigates, as reported by Decrypt and WuBlockchain. Separate reporting in the same cluster also links the phishing wave to a prior breach at shipping provider ShipMonk, which exposed Trezor customer personal information that may have fed into the targeting of the campaign. Similar phishing campaigns invoking fabricated hardware vulnerabilities have reportedly been observed targeting other hardware wallet users as well, suggesting the tactic is not isolated to Trezor.
What remains unresolved is how the attackers obtained access to Trezor's legitimate domain through the third-party provider, a point Trezor said it is still investigating. It is also not yet known how many users received the phishing email, whether any funds or credentials were compromised as a result, or what the eventual scope of the ShipMonk-related data exposure turns out to be. Users are being advised to avoid clicking links in any Trezor-branded emails until the company provides further updates on the investigation and confirms the domain has been fully secured.