Trezor Warns of Phishing Scheme Following Email Service Provider Breach
Hardware wallet provider Trezor alerted users after attackers breached its third-party email provider to distribute fake hardware flaw alerts.

Hardware wallet manufacturer Trezor has alerted its community regarding an unauthorized compromise after an external Trezor email breach exposed user communication channels. Cybercriminals gained unauthorized access to the firm's third-party newsletter service, utilizing the compromised infrastructure to distribute deceptive security notifications to customer inboxes.
According to Decrypt, the malicious email campaign attempted to deceive recipients by claiming that a newly discovered hardware vulnerability could expose their recovery seed phrases. The fraudulent messages urged users to click an external link to update their firmware and protect their digital assets from immediate compromise.
The deceptive communications directed victims to a sophisticated phishing portal engineered to harvest sensitive wallet credentials. Security analysts confirmed that the hardware wallets themselves were not compromised, emphasizing that the breach was strictly confined to the third-party email marketing provider utilized by the security firm.
Trezor reiterated to its user base that legitimate security operations never require users to disclose their seed phrases or enter recovery words on web interfaces. The incident underscores a persistent security risk in the crypto ecosystem, where attackers frequently target third-party service providers and supply chains rather than attempting to penetrate robust cryptographic hardware directly.
Phishing attacks leveraging authentic corporate communication platforms present severe risks because they bypass traditional email spoofing filters and appear entirely legitimate to casual observers. Security professionals advise digital asset holders to maintain strict operational hygiene and treat all unsolicited security notices with skepticism.
Moving forward, Trezor is conducting a comprehensive audit of its vendor relationships and communication infrastructure to prevent future supply chain incidents. Users are advised to verify firmware updates directly through the official application rather than interacting with external links sent via email.
Key takeaways
- Attackers breached Trezor's third-party email vendor to send fake security notifications.
- The phishing campaign falsely claimed a hardware flaw exposed wallet recovery phrases.
- Trezor confirmed that hardware devices remain secure and reiterated that seed phrases should never be shared online.
