Trezor Warns of Phishing Attack via Official Email Domain
Trezor warns of a sophisticated phishing campaign sent from its official domain following a series of data breaches at third-party partners.
This incident introduces a fresh layer of risk for customers, occurring just weeks after a data leak involving another Trezor partner.
The phishing message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” claims that a flaw in STM32 microcontrollers could compromise the security of a user’s recovery seed phrase. Trezor stated that the warning is entirely fraudulent and urged customers not to click any links within the email.
What makes this attack particularly dangerous is that the messages do not originate from an obviously fake address. Users reported receiving emails sent through “mailing.trezor.io,” making it nearly impossible to identify the scam simply by checking the sender’s details. Trezor confirmed a breach at its service provider and is currently investigating how attackers gained access to the legitimate domain.
Legitimate Domain Use Escalates Risks
The incident exposes a vulnerability that is particularly sensitive for self-custody companies. While the hardware wallet itself may remain technically secure, a compromised communication infrastructure allows attackers to target owners directly with far more convincing deceptions.
In this instance, the attackers exploited fears regarding hardware vulnerabilities to provoke immediate action. According to posts on Trezor’s community forums, the phishing page directed some recipients to an HTML file designed to harvest sensitive information. The company reiterated that it will never ask a customer to enter wallet details online.
Trezor has not yet disclosed how many individuals received the fraudulent emails, and there are currently no publicly confirmed losses of crypto assets resulting from this specific campaign.
New Case Follows Massive Customer Data Leak
The situation is compounded by a series of incidents involving Trezor’s external partners in recent weeks.
In August, the company revealed a breach at its logistics partner, ShipMonk. Initially, Trezor reported that 11,742 customers had their names, emails, phone numbers, and shipping addresses exposed, with another 1,947 people having their data partially compromised.
On September 2, the scale of the breach was significantly expanded. Trezor announced that ShipMonk had also stored older data from the period between November 2019 and August 2021, despite the provider repeatedly confirming in writing that the information had been deleted.
This added approximately 67,000 American customers to the list of those affected, with their names, emails, phone numbers, shipping addresses, and order numbers exposed. Between the initial group and the newly identified victims, the total data exposure now impacts over 80,000 individuals.
Risk Shifts Beyond the Hardware Wallet
This series of events highlights a recurring challenge for the hardware wallet industry. While private keys stay offline, manufacturers remain dependent on third-party firms for shipping, support, marketing, and customer communication.
Leaked personal details—such as names, emails, and home addresses—can be paired with access to legitimate email infrastructure to create highly sophisticated attacks. Following the ShipMonk incident, Trezor warned that stolen information could be used for phishing, fake phone calls, fraudulent letters, and could even pose a physical risk to affected customers.
This is a critical concern in the cryptocurrency sector, where obtaining a recovery phrase gives an attacker direct control over funds with no way to reverse the transaction.
While the latest breach does not indicate that Trezor’s hardware wallets themselves have been compromised, it shifts the focus from device protection to the security of the entire network of external providers. After the string of incidents over the past few weeks, this dependency has become a significant reputational and operational risk for the company.

Fill in necessary fields and publish