> Back to All Posts

Phishing Attack Hits Trezor Users After Email Provider Breach

Trezor phishing attack

Attackers have found a way to reach Trezor customers from an email address the company genuinely owns, which breaks the usual advice. On Wednesday, wallet owners began getting urgent alerts from help@trezor.io with the right branding and sender name. None of it came from the company. Trezor buyers are the target of a phishing attack that started with a break-in at the third-party firm handling its email.

The usual checks fail here, because the sender address survives every test a careful person would run. Trezor confirmed the scam, pulled the domain down, and started looking into how the attackers reached its mail systems. Its wallets and internal systems came through untouched.

What the fake alert claims

The messages arrive under the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and describe a chip-level flaw in the STM32 hardware inside Trezor cold wallets. They warn that the defect could let an attacker brute-force a recovery seed. That seed is the master key to a crypto wallet. Anyone who obtains one owns the funds.

The attackers chose that angle with care, because nothing moves a careful owner faster than panic about a seed. So the email builds an emergency around the one secret that matters, then offers a link that promises a fix. Every phishing attack landing in Trezor inboxes this week runs the same script. It borrows real terms, names a real part, and copies the tone of an engineering notice.

Why the phishing attack on Trezor users works so well

Most security guidance points people at the sender field and tells them to look for something off. A misspelled domain, an odd reply-to address, a free webmail account posing as a brand, an urgent tone nobody would use internally: those are the tells. None of them appear here. The mail comes from Trezor’s own domain and passes every sender check on the way in.

Spam filters wave it through to the main inbox, so a customer’s first sight is a warning from a trusted company. This phishing attack on Trezor owners works because every signal customers know to check comes back green. Trust built over years now turns against the people who extended it.

The targeting sharpens it further, since everyone on that list already owns a hardware wallet. Nobody has to guess who holds crypto. A phishing attack aimed at Trezor buyers converts at a rate no random blast will reach.

The weak link sits in the supply chain

The phishing attack now reaching Trezor users started outside the company, inside a supplier most customers never think about. A vendor gave way, and that has happened three times in under two years. The pattern matters more than the scam emails themselves.

The ShipMonk breach exposed home addresses

In August, attackers hacked ShipMonk, the firm that ships Trezor orders, and took records with full names, home addresses, emails, and phone numbers. The company first put the damage at close to 14,000 customers. That number did not hold.

A second review found another 67,000 American customers and pushed the total to 81,000. The stolen orders run from 10 May to 8 August 2026, and buyers in Brazil, Colombia, Italy, Portugal, Sweden, and the UK are on it too. Anyone who ordered in that window should assume their details are already out there.

Breach notices traced the break-in to a flaw in Metabase, the analytics platform running behind ShipMonk. Metabase disclosed in early August that criminals used a critical SQL injection zero-day to reach customer systems and steal data. ShipMonk later received extortion emails from the ShinyHunters gang.

An older breach with the same shape

January 2024 brought almost the same story, with a different supplier at the centre. Attackers broke into the support portal Trezor used then and took names, usernames, and email addresses from roughly 66,000 users. No wallet lost a coin, but the data entered circulation and stayed there.

What the leaked data lets criminals do

Put the two incidents side by side and the risk stops looking like a nuisance email. One group holds a verified list of wallet owners with home addresses and phone numbers. Another can send mail from a Trezor address customers already trust.

Cold calls that open with your real name and your most recent order date suddenly work. So do letters, and fake devices have turned up in the post after similar leaks. A phishing attack against Trezor buyers hits harder when the sender can quote what you bought and when it shipped. The fallout also lasts, since home addresses rarely change.

How Trezor owners can stay safe

Anyone caught in this phishing attack on Trezor customers can fall back on one rule that never bends. No real company will ask for your recovery seed, and no firmware update needs it. Anyone who asks is robbing you. Treat urgency in the message as the warning itself.

Check firmware and security notices inside the Trezor Suite app, or on a site you open yourself rather than through a link that arrived by email. A minute of friction costs nothing beside the contents of a wallet. That habit alone stops most of these.

Cutting your wider exposure helps too, and a good VPN encrypts traffic on shared networks while keeping your browsing away from your internet provider. Services such as NordVPN, Surfshark, and Windscribe also filter DNS, so known phishing domains never load. A separate email alias for hardware orders adds cover. Any phishing attack sent to Trezor buyers at that address gives itself away at once.

Final Thoughts

None of this required a flaw in the hardware, which is the part worth sitting with. The attackers borrowed trust Trezor spent years building. They walked in through a supplier nobody was watching, and a phishing attack that reaches Trezor buyers from an official address will fool careful people, because every check comes back clean.

So the burden shifts to the user, at least until vendors start defending customer data properly. Verify security news at the source, keep your recovery seed off every screen, and treat sudden panic as a sales tactic. Vendors will keep getting breached, and the habit matters more than any single alert.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.