Loading prices…
🩸BEARISH

Trezor Domain Used in Phishing Attack After Vendor Breach

Trezor's second third-party breach in two months, and this time attackers sent phishing from the vendor's own domain, not a look-alike address.

Hardware wallet maker Trezor warned users on Wednesday that phishing emails had been sent from its official domain after a third-party email provider was breached. The fraudulent message, titled 'Critical Security Alert: STM32 Entropy Vulnerability,' instructed customers to click a link to install a fake firmware update.

The phishing was convincing because it carried Trezor's legitimate domain and signatures, not the typical look-alike address most users have learned to spot. Crypto commentator Marcello Paz shared screenshots showing the email reached real Trezor customers, and Swiss rival BitBox reported a near-identical phishing email hitting its users the same day.

Why it matters

This is Trezor's second third-party breach in two months. In May, a breach at shipping provider ShipMonk initially exposed names, cities, and email addresses for roughly 13,700 customers, a figure Trezor later revised upward to 67,000 affected US customers. The vendor perimeter, not the device itself, is now the pattern.

The hardware itself has not been cracked this time. In June, Ledger's Donjon research team disclosed a lab-based laser fault-injection attack against the TROPIC01 secure element inside the Trezor Safe 7, but Trezor said no user funds were exposed. The recurring failure is operational: shipping labels, mailing lists, email infrastructure. Each one gives attackers a new vector into the same user base.

Market impact

The immediate cost is reputational, not technical. Users who clicked the link and entered seed phrases are exposed, and Trezor has not yet disclosed whether any funds were lost. The bigger read is for self-custody at scale: every third-party integration expands the attack surface beyond what a hardware wallet can secure on its own.

The pattern is industry-wide. A 2020 breach at Ledger exposed more than 270,000 customers, and Ledger users have continued reporting scam phone calls and physical letters years later. Trezor has taken down the affected domain and is investigating how attackers obtained legitimate sender credentials. For now, the safest read is to never trust a hardware wallet update that arrives by email.

Related tokens
$BTC

Frequently asked questions

  1. What happened with Trezor's domain on Wednesday?

    Trezor warned users that phishing emails had been sent from its official domain after a third-party email provider was breached. The fraudulent message, titled 'Critical Security Alert: STM32 Entropy Vulnerability,' linked to a fake firmware update.

  2. How many customers were exposed in the earlier ShipMonk breach?

    Trezor's May disclosure initially listed 13,700 affected customers. The company later revised that figure upward to 67,000 affected US customers after the scope expanded.

  3. Was the Trezor Safe 7 hardware itself compromised?

    In June, Ledger's Donjon research team disclosed a lab-based laser fault-injection attack against the TROPIC01 secure element in the Trezor Safe 7. Trezor said no user funds were exposed in that disclosure.

  4. Did BitBox face the same phishing campaign?

    Yes. On the same day as the Trezor phishing emails, Swiss hardware wallet maker BitBox reported a near-identical phishing email hitting its users.

  5. How should users respond to a hardware wallet update email?

    Don't click it. Trezor has taken down the affected domain and is investigating; the safe rule is to never trust a hardware wallet update that arrives by email, and instead update firmware through the official wallet app.

Source attribution
Aggregated from TheBlock · Verified · Last refreshed 1h ago
Open original →