Trezor Warns of Phishing Campaign After Third-Party Email Breach
Attackers are leveraging a vendor breach to trick hardware wallet users into revealing their recovery phrases.
Trezor has alerted its customers to a sophisticated phishing campaign following a security breach at one of its third-party email providers. The incident allows attackers to send fraudulent messages to users in an attempt to steal cryptocurrency funds.
The malicious emails are titled "Critical Security Alert: STM32 Entropy Vulnerability." According to Trezor, these messages falsely claim that a hardware flaw in the STM32 microcontrollers used in Trezor devices could expose user recovery phrases. The emails direct users to a fraudulent website where they are prompted to enter their recovery phrases, which would grant attackers full access to their wallets. In a message to users, Trezor stated, "Our third‑party e‑mail provider has been breached... Do not click on any link."
A Pattern of Vendor Vulnerabilities
This latest incident is part of a broader series of security challenges involving Trezor's external partners. The company previously dealt with a support portal breach in January 2024 that affected approximately 66,000 users. Additionally, a breach at shipping partner ShipMonk exposed customer data; while initially reported as affecting 13,689 customers, an update on September 4 indicated the number of exposed users had risen above 80,000, including names, phone numbers, and addresses.
The Risk of Technical Social Engineering
This attack is particularly dangerous because it leverages technical jargon to create a sense of urgency and legitimacy. By referencing a specific hardware component like the STM32 microcontroller, attackers aim to bypass the skepticism of experienced users. The campaign targets the recovery phrase—the most sensitive piece of information in a hardware wallet ecosystem—which, if compromised, renders the physical security of the device irrelevant.
Systemic Third-Party Risks
While Trezor confirmed that its internal systems were not breached and that private keys, wallets, and recovery backups stored on devices remain secure, the incident highlights a systemic risk. It demonstrates that even when a hardware device is mathematically and physically secure, the surrounding infrastructure—such as email and shipping vendors—can be used as a vector for social engineering.
Users are advised to remember that Trezor will never ask for a recovery phrase via email or on any website. Security experts continue to monitor for further iterations of the campaign as attackers refine their lures to target the hardware wallet community.