CRYPTOCURRENCY NEWS

Trezor Email Breach Enabled Phishing From Its Own Domain

Trezor says a third-party email breach allowed attackers to send phishing messages from the hardware-wallet maker's own domain, a rare escalation that strips users of the usual tell of a fake sender address.

Share:

Trezor Says a Third-Party Email Breach Enabled Phishing

What Trezor Says Happened

At the center of the Trezor email breach is an uncomfortable detail: the compromise sat with a third-party email provider, not with Trezor’s hardware or core systems, yet it was enough to weaponize the company’s trusted communications channel. Trezor said the breach let attackers push phishing emails to users, according to Unchained’s reporting. For related coverage, see Bitcoin $72–73K Level: ETF Realized Price and Coinbase Premium.

The malicious campaign leaned on urgency, using the subject line “Critical Security Alert: STM32 Entropy Vulnerability” to prompt action, and Trezor warned recipients not to click the links inside. The pretext, that a genuine STM32 entropy flaw required users to update their devices through the emailed instructions, is the phishing lure itself and not a verified vulnerability, according to unconfirmed reporting. For related coverage, see XRP ETFs Draw Nearly $2 Million Despite Slower Momentum.

Trezor’s standing security guidance is the relevant defense here: support will never ask for a recovery seed, and users should never enter a wallet backup without first initiating recovery and confirming it on the device, per the company’s phishing article. Attackers typically chase wallet backups because a seed phrase, once entered on a malicious page, hands over full control of funds.

Attackers Sent Phishing From Trezor’s Own Domain

The Own-Domain Detail in the Report

What separates this campaign from routine crypto phishing is the sender. Rather than a lookalike domain or a spoofed display name, the messages reportedly came from Trezor’s own domain, meaning the usual advice to scrutinize the address offered users little protection in this case.

The available reporting does not include email samples, the specific domain address, or the technical delivery mechanism, so the exact path from a provider compromise to authenticated-looking mail remains undescribed. Trezor was not the only wallet maker in attackers’ sights: BitBox warned its customers about a similar impersonation campaign on the same day, an industry reaction reported by Unchained rather than an independently confirmed BitBox statement.

What Remains Unclear About the Trezor Email Breach

Scope, Impact and Response

The fetched reporting does not establish how many recipients received the phishing mail, whether any funds were lost, the identity of the email provider, or the current status of the malicious domain. These gaps reflect the limits of the available material, not evidence that the incident was minor or fully contained.

Context comes from a separate incident Trezor has disclosed in more detail. In its official FAQ, updated September 4, 2026, Trezor says 80,689 customers were affected by a breach at shipping provider ShipMonk, a figure the company has published even though the headline reporting suggested no combined total existed.

Separate ShipMonk breach

Customers affected, according to Trezor’s official FAQ

Trezor’s official FAQ, updated September 4, 2026, states that 80,689 customers were affected by the separate ShipMonk shipping-provider breach. This is not a count of email-phishing recipients; no fetched evidence establishes a causal link between the incidents.

The ShipMonk disclosure, originally dated August 13 and updated after Trezor learned on September 2 that older order data was also involved, initially listed 11,742 customers with full exposure and 1,947 with partial exposure. The September update added roughly 67,000 US customers whose order data from November 2019 through August 2021, including names, emails, phone numbers, shipping addresses and order numbers, had survived despite repeated written deletion assurances against a stated 90-day retention window.

Trezor says its own systems were not compromised in the ShipMonk incident and its devices remained secure, a statement that does not extend to the scope of the later email-provider attack. No fetched evidence links the shipping breach causally to the current phishing campaign, and the claim that ShipMonk data supplied the targets remains unverified.

The pattern is now familiar across the sector, with peers such as SafePal disclosing exposure of order information for nearly 40,000 customers. The through-line connecting these events is that hardware wallets remain secure by design while the customer data and communication channels around them, held by shipping and email vendors, keep becoming the softer target.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Stay ahead of the market

Get daily crypto insights delivered to your inbox.

Related Articles

View all →