Trezor Faces Vendor Breaches as Phishing Attack Threatens Users

Trezor Warns Of Phishing Campaign After Third-Party Email Provider Breach
Disclaimer: The information provided is for informational purposes only. All content, including news articles, analysis, opinions, and commentary, does not constitute financial, investment, legal, or trading advice. Cryptocurrency markets are highly volatile and involve significant risk. Readers are strongly encouraged to conduct their own research. CryptoMoonPress is not responsible for any financial losses or damages resulting from reliance on the information.

Trezor has warned customers about a phishing campaign after a third-party email provider used by the hardware-wallet company was breached, allowing attackers to send a fake security alert that appeared to come from Trezor. The email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” falsely claimed that a vulnerability in STM32 chips could put users’ recovery phrases at risk. 

Trezor posted on X and stated that the message was fraudulent, urged recipients not to click its links and said it had taken down the associated domain. The company is investigating how attackers gained access to its legitimate email infrastructure.

The incident comes shortly after a separate breach at Trezor’s logistics provider exposed data belonging to more than 80,000 customers, adding to concerns about how third-party services can create security risks for cryptocurrency companies and their users.

Trezor Confirms Email Provider Breach Behind Phishing Campaign

Trezor confirmed that its third-party email provider had been breached and warned users about the fake STM32 security alert. The company said it had taken down the domain used in the campaign and was investigating how attackers gained access to its legitimate domain.

The phishing email was designed to resemble a genuine security advisory. Users reported receiving messages that appeared to come from legitimate Trezor addresses, including help@trezor.io.

Reports on the Trezor forum also said the sender appeared legitimate, while the linked website requested sensitive wallet information. Other forum users reported that the phishing emails appeared to have been sent through Trezor’s mailing infrastructure, although the technical details remain under investigation. The distinction between the email infrastructure and Trezor’s wallet technology is important. Trezor has not said that its hardware wallets or recovery seeds were compromised. 

The immediate risk is instead phishing. Trezor’s security guidance says legitimate communications will never ask users to provide their wallet backup or recovery seed, which can give an attacker control over cryptocurrency if disclosed. The campaign has drawn concern because the message looked convincing.

Crypto commentator FatMan said the phishing email appeared to come from Trezor’s official domain and warned about potential financial losses.

BitBox Reports Similar Phishing Activity As Earlier Trezor Breach Adds Context

Hardware-wallet company BitBox said its preliminary review found that its newsletter provider was likely compromised after phishing emails were sent to subscribers. The company said multiple Bitcoin companies appeared to have been targeted and that they seemed to share the same newsletter provider.

BitBox said it warned subscribers, contacted the provider and reported the phishing domains. The company said most of the phishing links had already been taken down, while its investigation was continuing. The statement does not establish that the Trezor and BitBox incidents were carried out by the same attackers, but the apparent involvement of a shared newsletter provider is relevant. 

The Trezor phishing campaign also follows the company’s separate breach at ShipMonk, its logistics provider. Trezor initially disclosed that 13,689 customers were affected. An update later added approximately 67,000 U.S. customers whose older records had remained in ShipMonk’s systems, bringing the reported total to 80,689 customers.

The exposed information included names, email addresses, phone numbers, shipping addresses and order numbers. Trezor said the information could increase the risk of phishing, fraudulent calls and physical-security threats. The company has not said that the ShipMonk incident compromised its wallet products or customer funds. 

The earlier breach does not establish a direct connection to the current email-provider incident. It does, however, show how third-party services can become part of the security risk around cryptocurrency products.

The current phishing campaign relies on a trusted communication channel, while the earlier incident exposed information that could make later attempts at impersonation more convincing. Moreover, the latest incident is Trezor’s “third vendor breach” in four weeks, referring to the email-provider incident and earlier exposures.

 

Mayank Kumar 150x150

Mayank Kumar

Author at cryptomoonpress

Mayank Kumar has been a gamer since 2006, starting with the Game Boy and Nintendo DS. That passion has since...

Niharika Deshpande 150x150 1

Niharika Deshpande

Editor at cryptomoonpress

Niharika Deshpande is a crypto editor and journalist at CryptoMoonPress, with over four years of experience covering cryptocurrency, blockchain, and...

Last updated September 10, 2026
Share on: FB X LinkedIn
Written by Mayank Kumar Verified by Niharika Deshpande