Trezor Users Targeted In Sophisticated Phishing Campaign After Email Provider Breach

10-Sep-2026 mpost.io
Trezor Users Targeted In Sophisticated Phishing Campaign After Email Provider Breach

Hardware wallet manufacturer Trezor, the second-largest producer of devices for storing cryptocurrency, has warned users of a phishing email campaign launched after a breach of its third-party email provider. The company confirmed that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” did not originate from Trezor and urged customers not to click any links it contains.

According to the warning posted on X, attackers exploited the compromised infrastructure to send fraudulent security alerts from a spoofed version of the company’s official mailing domain, passing standard sender authentication checks. Trezor stated that it has taken down the domain used in the attack and is investigating how the hackers gained access to its legitimate domain, though the name of the affected provider and the number of recipients remain undisclosed.

The phishing email was designed to appear as an urgent security notice, claiming that approximately one in four Trezor devices contained a factory defect in the random number generator of their STM32 microcontrollers. The message asserted that this flaw allegedly made wallet seed phrases insufficiently protected against brute force attacks, prompting recipients to follow a link to check whether their device model was affected.

What distinguishes this campaign from conventional phishing attempts is its technical credibility. One recipient, Marcello Paz, reported that the email successfully passed Gmail’s sender verification, with DKIM, SPF, and DMARC authentication checks all showing as valid for the trezor.io domain. The message was sent from “Trezor Security” through a Sendinblue campaign, giving it an appearance of legitimacy that could deceive even security-conscious users.

The incident underscores a growing risk for cryptocurrency users: attackers who compromise trusted communications infrastructure can bypass email authentication protocols entirely, since fraudulent messages originate from genuinely authorized sending domains rather than spoofed ones.

Second Security Incident for Trezor in Recent Months

The breach adds to a series of security disclosures affecting the hardware wallet sector and Trezor specifically. In August, the company revealed that its logistics partner ShipMonk had suffered unauthorized access, exposing order information spanning May 10 to August 8. The incident affected 13,689 users across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. For 11,742 customers, personal data was fully compromised, while 1,947 others had names, cities, and email addresses exposed. Trezor subsequently disclosed on September 4 that an additional 67,000 US customers were affected. Independent estimates suggested the total impact could exceed 80,000 clients.

Trezor notified affected users of the ShipMonk breach at the time and warned of elevated phishing risk — a forecast that has now materialized. The company has not indicated whether the two incidents are connected or whether customer data obtained in the earlier logistics breach was used to target recipients of the current phishing campaign.

Users are advised to treat any email requesting clicks or personal information with heightened caution and to verify security notices directly through official Trezor channels rather than embedded links.

The post Trezor Users Targeted In Sophisticated Phishing Campaign After Email Provider Breach appeared first on Metaverse Post.

Also read: Crypto Millionaires Face a New Source-of-Wealth Test
WHAT'S YOUR OPINION?
Related News