Tag: phishing campaign

  • Trezor Warns Users After Hackers Breach Email Provider to Send Phishing Alerts

    Trezor Warns Users After Hackers Breach Email Provider to Send Phishing Alerts

    Trezor Warns Users of Phishing Campaign Exploiting Legitimate Email Infrastructure

    Hardware wallet manufacturer Trezor alerted users on Wednesday, September 9, 2026, about a sophisticated phishing campaign that exploited the company’s third-party email provider to distribute a fraudulent security notice. While Trezor wallets themselves remained unaffected, the attack targeted something more difficult to secure than software: user trust in communications from verified senders.

    Fabricated Vulnerability Sent from Verified Domain

    The phishing email carried the subject line: “Critical Security Alert: STM32 Entropy Vulnerability.” The message claimed Trezor engineers had discovered a design defect in STM32 chips used in the company’s products, warning that one in four devices could become compromised and that recovery phrases might lack sufficient randomness or entropy. This language closely mirrored issues described in the recent Coldcard firmware exploit.

    According to a report by Decrypt, Trezor identified the message as fraudulent and urged recipients not to click any links.

    Email Passed All Authentication Checks

    What made the campaign particularly effective was its delivery mechanism. One recipient reported the email originated from help@trezor.io, traversed the Sendinblue campaign infrastructure, and successfully passed DKIM, SPF, and DMARC authentication checks—technical validations typically used to verify sender legitimacy.

    Trezor confirmed it had disabled the domain used for the malicious alerts and launched an investigation into how threat actors accessed its legitimate sending infrastructure. The company issued its public warning shortly after 4:30 PM Eastern Time on September 9, just hours after users began reporting the suspicious emails.

    Broader Pattern Suggests Compromised Marketing Provider

    The breach may extend beyond Trezor. Nick Neuman, co-founder and CEO of Casa, indicated a similar trend appears to be affecting BitBox users, suggesting a common marketing email provider may have been compromised.

    This highlights a systemic vulnerability: wallet manufacturers can strengthen device security, but their brand reputation remains exposed through third-party dependencies—including email service providers, shipping partners, and payment processors—that they do not fully control.

    Distinction Between Data Breaches and Device Exploits

    Security analysts emphasize the critical difference between data breaches and device exploits. A previous Cryptopolitan report revealed phishing attempts against Ledger users have expanded into physical mail, yet these incidents compromise identity and contact information rather than directly exposing financial assets.

    The 2026 hardware wallet security landscape illustrates this distinction clearly:

    • SafePal disclosed an authorization error in an order tracking plugin exposed data for approximately 39,798 customers, confirming seed phrases, private keys, and wallet credentials were not compromised.
    • Trezor’s ShipMonk breach ultimately affected 80,689 customers after the company discovered legacy U.S. order records from 2019–2021 were also exposed.
    • Ledger’s Global-e incident in January exposed customer order details and contact information, though the exact number of affected users was not disclosed.

    In an August comparison, Memeburn correctly categorized Ledger, Trezor, and SafePal under “data breaches” while identifying Coldcard as a “device exploit.” The 13,689 figure Memeburn cited for Trezor predates the company’s September 4 update.

    Coldcard Exploit Represents Distinct Threat Category

    Coldcard stands apart from the data exposure incidents. According to Galaxy Research on August 14, the firmware flaw resulted in 190 confirmed victims, over 86,000 affected addresses, and at least $112.7 million (1,778.84 BTC) in stolen assets. Other estimates place potential losses near $130 million.

    Leaked Purchase Data Fuels Industrialized Phishing

    The danger of exposed shipping records lies in their utility for targeted attacks. Chainalysis estimated crypto scams and fraud stole $17 billion in 2025, with impersonation scams growing more than 1,400% year over year. The firm also found scams linked to AI vendors generated 4.5 times more revenue per operation than those without such connections.

    A hardware wallet purchase record—combining name, email, phone number, home address, and confirmation of crypto security device ownership—provides criminals with the context to craft highly convincing emails, calls, letters, or even physical approaches.

    Security Perimeter Extends Beyond the Device

    The lesson from Trezor’s latest incident is not that hardware wallets failed. It is that the security perimeter now encompasses the entire ecosystem surrounding them, and attackers increasingly need only a single trusted-looking message to breach defenses.

  • Trezor Email Provider Breached Amid Spread of Fake Wallet Security Alert

    Trezor Email Provider Breached Amid Spread of Fake Wallet Security Alert

    Trezor Warns Customers of Phishing Campaign Following Third-Party Email Provider Breach

    Hardware wallet manufacturer Trezor has alerted users to a phishing campaign targeting its customers after attackers compromised a third-party email provider. The fraudulent message mimics a critical security advisory, attempting to lure recipients into revealing sensitive wallet information.

    Fake Security Alert Mimics Legitimate Warning

    The phishing email carries the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” The message falsely claims a major security risk affects Trezor hardware wallets, creating urgency designed to pressure users into clicking malicious links. Those links direct victims to a website requesting confidential wallet details, including recovery seeds.

    Trezor confirmed the email is fraudulent in a public statement:

    The email…is not coming from us, and it’s a phishing attempt.

    Attackers Exploited Legitimate Domain

    The company has taken down the domain used in the campaign and is investigating how threat actors gained access. Because the emails originated from a genuine domain, they bypassed typical sender-verification checks, making the deception more convincing even for security-conscious users who routinely inspect sender addresses.

    Trezor has not disclosed the identity of the compromised email provider, the number of customers who received the malicious message, or whether any customer data was accessed during the breach. The firm also reports no cryptocurrency losses linked to this specific campaign.

    Separate Incident Involving Shipping Provider ShipMonk

    This email provider breach follows an earlier security incident involving Trezor’s shipping partner, ShipMonk. That breach exposed names, email addresses, phone numbers, and delivery addresses. Trezor later disclosed an additional 67,000 U.S. customers were affected.

    The company has not connected the two incidents or suggested the same threat actors are responsible for both.

    Recommended Actions for Affected Users

    • Do not click any links in the suspicious email.
    • Delete the message immediately.
    • Never enter your wallet recovery seed on any website or share it with anyone.

    Trezor continues to investigate the email provider breach and has pledged further updates as the investigation progresses.