RUECAT DEX
All news
The Block 3h ago

Trezor Confirms Phishing Campaign Triggered by Third-Party Vendor Data Compromise

Hardware wallet manufacturer Trezor warns users of phishing emails sent through legitimate domains after a supplier security incident.

A secure hardware device shielded against a Trezor phishing breach on a dark cybersecurity background.

Leading hardware wallet manufacturer Trezor has alerted its global user base regarding a sophisticated social engineering campaign originating from legitimate communication domains. The incident stems from an unauthorized breach of an external service provider, allowing malicious actors to send deceptive messages to targeted customers.

According to reporting from The Block, the company confirmed that attackers leveraged compromised third-party infrastructure to dispatch fraudulent security alerts designed to trick users into disclosing sensitive recovery phrases. Because the emails originated from authenticated server records, standard spam filters struggled to identify and flag the malicious correspondence.

This security advisory follows an earlier breach affecting logistics and fulfillment partner ShipMonk, which resulted in the exposure of customer contact details and shipping records. Attackers frequently cross-reference stolen logistical datasets with email dispatch tools to execute highly convincing spear-phishing operations against crypto hardware holders.

Trezor reiterated to its community that physical hardware wallet integrity remains uncompromised and emphasized that legitimate corporate representatives will never ask users for their secret recovery seed phrases. Self-custody security models depend entirely on keeping private mnemonic keys offline and completely isolated from any internet-connected software interface.

Cybersecurity experts warn that supply chain vulnerabilities represent one of the most pressing threats to decentralized asset custody. Even when core cryptographic hardware remains secure, peripheral service providers such as mailing lists, customer support platforms, and delivery contractors often provide attackers with vector points.

Users have been strongly urged to inspect all incoming communications with extreme skepticism, avoid clicking embedded links in urgent security warnings, and verify firmware updates exclusively through official standalone desktop applications.

Key takeaways

  • Trezor warned customers about phishing emails stemming from an external vendor breach.
  • The malicious emails leveraged legitimate domains following an earlier leak at shipping partner ShipMonk.
  • Hardware wallet seeds remain safe provided users never enter their recovery phrases online.
Source: The Block