Trezor Users Targeted In Sophisticated Phishing Campaign After Email Provider Breach

Hardware wallet manufacturer Trezor, the second-largest producer of devices for storing cryptocurrency, has warned users of a phishing email campaign launched after a breach of its third-party email provider. The company confirmed that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” did not originate from Trezor and urged customers not to click any links it contains.
According to the warning posted on X, attackers exploited the compromised infrastructure to send fraudulent security alerts from a spoofed version of the company’s official mailing domain, passing standard sender authentication checks. Trezor stated that it has taken down the domain used in the attack and is investigating how the hackers gained access to its legitimate domain, though the name of the affected provider and the number of recipients remain undisclosed.
The phishing email was designed to appear as an urgent security notice, claiming that approximately one in four Trezor devices contained a factory defect in the random number generator of their STM32 microcontrollers. The message asserted that this flaw allegedly made wallet seed phrases insufficiently protected against brute force attacks, prompting recipients to follow a link to check whether their device model was affected.
What distinguishes this campaign from conventional phishing attempts is its technical credibility. One recipient, Marcello Paz, reported that the email successfully passed Gmail’s sender verification, with DKIM, SPF, and DMARC authentication checks all showing as valid for the trezor.io domain. The message was sent from “Trezor Security” through a Sendinblue campaign, giving it an appearance of legitimacy that could deceive even security-conscious users.
The incident underscores a growing risk for cryptocurrency users: attackers who compromise trusted communications infrastructure can bypass email authentication protocols entirely, since fraudulent messages originate from genuinely authorized sending domains rather than spoofed ones.
Second Security Incident for Trezor in Recent Months
The breach adds to a series of security disclosures affecting the hardware wallet sector and Trezor specifically. In August, the company revealed that its logistics partner ShipMonk had suffered unauthorized access, exposing order information spanning May 10 to August 8. The incident affected 13,689 users across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. For 11,742 customers, personal data was fully compromised, while 1,947 others had names, cities, and email addresses exposed. Trezor subsequently disclosed on September 4 that an additional 67,000 US customers were affected. Independent estimates suggested the total impact could exceed 80,000 clients.
Trezor notified affected users of the ShipMonk breach at the time and warned of elevated phishing risk — a forecast that has now materialized. The company has not indicated whether the two incidents are connected or whether customer data obtained in the earlier logistics breach was used to target recipients of the current phishing campaign.
Users are advised to treat any email requesting clicks or personal information with heightened caution and to verify security notices directly through official Trezor channels rather than embedded links.
Disclaimer
In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.
About The Author
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
More articles
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.



