Trezor warns users of email provider breach, phishing attacks

Cryptocurrency wallet maker Trezor is warning its users of a phishing attack that appears to be linked to a recent breach of its email provider. The company has confirmed that threat actors have been sending fake “critical security alert” emails to affected customers, claiming that their hardware wallets are vulnerable to hacking due to a supposed flaw in the microcontrollers used by Trezor.

The emails, which appear to come from the official Trezor domain (help@trezor.io), claim that hackers could potentially use brute-force cracking to access users’ seed phrases and steal their cryptocurrency. However, Trezor has explicitly stated that these emails are not legitimate and should be ignored. The company has also taken steps to mitigate the situation by taking down the compromised domain.

This phishing attack is just the latest in a string of issues facing Trezor customers. In August, the company disclosed a data breach involving its shipping and logistics provider, ShipMonk. Initially, it was reported that nearly 14,000 customers were affected, but a subsequent investigation revealed that an additional 67,000 US customers had also been impacted, bringing the total to over 81,000. The breach exposed customers’ order data, including full names, shipping addresses, email addresses, and phone numbers.

The ShipMonk breach was attributed to a vulnerability in the Metabase analytics platform, which allowed hackers to exploit a critical SQL injection zero-day vulnerability. This is not an isolated incident – in January 2024, Trezor disclosed another data breach after its third-party support ticketing portal was compromised. In this instance, attackers accessed data from approximately 66,000 users.

It’s worth noting that once attackers gain access to valid credentials, prevention measures become much less effective. A recent report found that only 37% of an attacker’s actions are blocked when they have valid login credentials. This highlights the importance of robust security measures beyond just prevention, including detection and response capabilities.

For Trezor users, this phishing attack serves as a reminder to remain vigilant and skeptical of unsolicited emails, especially those claiming to be from official sources with urgent security alerts. It’s essential for users to verify the authenticity of any email before taking action, and to report suspicious activity to the company. As the cybersecurity landscape continues to evolve, it’s crucial for individuals and companies alike to stay informed and take proactive steps to protect themselves against these types of threats.

In light of this incident, we recommend that Trezor users exercise extreme caution when receiving emails from help@trezor.io or any other email claiming to be from the company. Verify the authenticity of the email by contacting Trezor directly through a trusted channel, and never click on links or provide sensitive information in response to unsolicited emails. By staying vigilant and taking proactive steps to protect yourself, you can minimize the risk of falling victim to phishing attacks and other cybersecurity threats.


Source: Bleeping Computer — 2026-09-10