Trezor Suffers Sophisticated Phishing Attack Following Email Provider Compromise
Leading hardware wallet manufacturer Trezor has once again found itself at the center of a significant supply chain security incident. On September 9th, Trezor confirmed that a third-party email service provider it utilizes had been compromised. Attackers exploited this breach to dispatch highly deceptive security warning emails, even leveraging email infrastructure associated with Trezor’s legitimate domain. This made the phishing attempts almost indistinguishable from genuine official communications, posing a severe threat to user security.
Elaborate Phishing Campaign Mimics “STM32 Critical Vulnerability”
The fraudulent emails, titled “Critical Security Alert: STM32 Entropy Vulnerability,” falsely claimed a severe random number and entropy flaw within the STM32 microcontrollers used in Trezor devices. The message asserted that this purported vulnerability could drastically reduce the security of users’ wallet backups, urging immediate security checks. This tactic was designed to panic users into revealing sensitive wallet information.
Trezor swiftly issued a public clarification, unequivocally stating that these warnings were not legitimate company communications but rather a sophisticated phishing attack. The company strongly advised users against clicking any links within the emails or inputting any wallet-related information. Trezor also confirmed it had deactivated the compromised domain and initiated an investigation into how attackers gained access to its legitimate domain-associated systems.
Further insights into the attack’s sophistication emerged as users who received the emails shared email headers on the official Trezor forum. These headers indicated the emails were sent via mailing.trezor.io. Disturbingly, many users reported that the emails successfully passed common sender authentication protocols such as SPF, DKIM, and DMARC. This critical detail suggests that the incident wasn’t merely a case of spoofing a trezor.io address with similar-looking characters. Instead, attackers likely gained direct access to a trusted third-party email system, enabling them to exploit a legitimate sending channel.
Independent security researchers have also highlighted that some malicious links initially redirected through Trezor’s own email tracking subdomain. This advanced technique made it exceptionally difficult for users to identify the anomaly, even when scrutinizing sender addresses or hovering over links. While some research points to Brevo as the implicated email platform, Trezor has not yet officially disclosed the name of the compromised supplier, so this remains unconfirmed.
A Disturbing Trend: Second Third-Party Risk Incident in Weeks
This latest phishing incident is particularly concerning as it comes mere weeks after Trezor’s previous encounter with a third-party supply chain data breach.
In August, Trezor revealed that its logistics partner, ShipMonk, had been compromised. Initially, the breach was confirmed to have exposed the names, email addresses, phone numbers, and shipping addresses of 11,742 customers, with partial data leakage for an additional 1,947 individuals. A subsequent investigation update in early September uncovered that ShipMonk’s systems still retained old order data that should have been contractually deleted. This discovery expanded the impact to approximately 67,000 more U.S. customers, bringing the total number of affected individuals to an estimated 81,000.
The data exposed in the ShipMonk breach included names, email addresses, phone numbers, delivery addresses, and order numbers. At the time, Trezor specifically warned that this information could be weaponized for highly targeted phishing emails, phone scams, or even physical social engineering attacks.
While both incidents involve third-party compromises, there is currently no public evidence to suggest a direct link between the ShipMonk data breach and the latest email service intrusion, nor is it confirmed that the recipient list for this phishing campaign originated from the previously leaked data.
“Official Sender” No Longer a Guarantee of Security
Perhaps the most critical takeaway from this incident is the alarming realization that traditional methods of identifying phishing emails are becoming obsolete. Trezor’s long-standing security guidelines consistently advise users never to input or provide their recovery seed or wallet backup online or to anyone. Trezor emphatically states that the company will never proactively request wallet backups, PINs, passwords, or verification codes. Any notification demanding “mnemonic verification” or prompting users to enter wallet backups onto a webpage should be immediately recognized as a scam.
This incident underscores that even if an email appears to originate from a genuine official domain, passes SPF or DKIM authentication, or even if a link initially points to an official subdomain, these indicators are no longer sufficient to guarantee the trustworthiness of the email’s content.
For the broader hardware wallet industry, this event starkly highlights that “cold storage,” while securing private keys offline, does not eliminate all associated risks. While private keys remain isolated, critical components like customer databases, logistics providers, customer service platforms, and email services are still intertwined with traditional cloud supply chains. Attackers don’t necessarily need to crack the hardware wallet itself; successfully tricking a holder into voluntarily surrendering their seed phrase is equally effective in gaining control of their digital assets.
As of September 10th, Trezor has not yet disclosed the exact number of recipients affected by this phishing incident, the specific name of the third-party email supplier, or whether any users have suffered losses of cryptocurrency assets. The investigation remains ongoing.
Disclaimer: This article is intended solely to provide market information. All content and views are for reference only, do not constitute investment advice, and do not represent the views and positions of BlockBeats. Investors should make their own decisions and trades. The author and BlockBeats will not bear any responsibility for direct or indirect losses incurred by investors’ transactions.