Cryptocurrency hardware wallet maker Trezor is warning its customers of a phishing attack that’s exploiting a recent breach of its third-party email provider. The attackers are sending fake “critical security alert” emails claiming to inform users about a vulnerability in the microcontrollers used by Trezor cold storage wallets, but this is actually a ploy to trick people into clicking on malicious links.
Trezor has confirmed that the company’s domain was compromised, allowing hackers to send these phishing emails. The firm has taken down its email provider and is investigating how the breach occurred. If you’re a Trezor customer, be aware of an email supposedly from help@trezor.io claiming there’s a “hardware microcontroller vulnerability” in your wallet that could expose your seeds to brute-force cracking. Don’t click on any links or provide sensitive information – this is a phishing attempt.
This latest incident follows another data breach disclosed by Trezor last month, where hackers stole customers’ order data from its shipping and logistics provider ShipMonk. Initially, the company said around 14,000 customers were affected, but further investigation revealed an additional 67,000 U.S. customers were also impacted, bringing the total to over 81,000. Customers in other countries, including Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom, also received orders between May 10 and August 8, 2026.
Trezor explained that ShipMonk’s systems were compromised by exploiting a vulnerability in the Metabase analytics platform. This zero-day vulnerability allowed attackers to gain administrator access and steal data. It’s worth noting that Metabase itself disclosed this incident early in August, stating that threat actors had exploited a critical SQL injection flaw to breach customer instances.
The ShinyHunters extortion gang has also been implicated in this breach, as ShipMonk received extortion emails demanding payment in exchange for not releasing the stolen data. This is just another reminder of how quickly attackers can move after breaching a system, and why prevention should be an ongoing effort.
Trezor’s customers may want to take a closer look at their email accounts and be cautious about any suspicious communications. The company has assured users that they’re taking steps to protect their data and prevent further attacks. As always, vigilance is key – remain aware of potential phishing attempts and never click on unsolicited links or provide sensitive information without verifying the authenticity of the request.
In light of this incident, it’s essential for all users to be mindful of their email communications and stay informed about potential security threats. If you’re unsure about the legitimacy of an email, err on the side of caution and report it to your service provider or relevant authorities.
Source: Bleeping Computer — 2026-09-10