uMaHF0G5M1jYL9t88qHEEkQggU6GJ5wTZlhvItt7
Bookmark

Trezor Email Provider Breach Exposes Users to Sophisticated Phishing Campaign

Trezor warns of a phishing campaign after a third-party email provider breach allowed fraudulent security alerts to pass SPF, DKIM and DMARC checks.
Trezor phishing email warning linked to a third-party provider breach and fraudulent security verification campaign.

Trezor has warned customers about a sophisticated phishing campaign launched through compromised infrastructure belonging to a third-party email provider. The attackers used legitimate Trezor-associated systems to distribute fraudulent security alerts that appeared to come directly from the hardware wallet company.

Trezor said the malicious email was titled “Critical Security Alert: STM32 Entropy Vulnerability” and urged customers not to open links contained in the message. According to Trezor, The company disclosed that its third-party email provider had been breached and said it had removed the affected domain while investigating how the attackers gained access to infrastructure connected with its legitimate online systems.

Trezor has not disclosed the identity of the affected email provider or how many customers received the fraudulent messages.

Trezor Phishing Emails Passed Standard Security Checks

The campaign was particularly difficult to identify because the messages reportedly lacked several indicators commonly associated with phishing attempts.

Screenshots of the emails showed “Trezor Security” as the sender and displayed the legitimate-looking address help@trezor.io. Gmail also identified mailing.trezor.io as the delivery source, while trezor.io appeared as the domain responsible for signing the messages.

The emails reportedly passed SPF, DKIM and DMARC authentication checks. These mechanisms are designed to help mail systems determine whether a message was sent through authorized infrastructure and whether its contents or domain credentials have been tampered with.

As a result, recipients had fewer conventional warning signs to rely on, while automated email security systems were less likely to reject or flag the messages.

The incident highlights a particular risk associated with compromised trusted infrastructure: authentication can establish that an email was sent through authorized systems without proving that the message itself is legitimate.

Fake Security Alert Targets Trezor Wallet Users

The fraudulent campaign centered on an alleged vulnerability involving the entropy, or randomness, used by Trezor devices to protect cryptographic information.

The attackers used the supposed security flaw to create urgency and direct recipients toward a fake verification process. The objective was to persuade users to provide information that could potentially compromise their cryptocurrency wallets.

A Trezor forum user reported that an offline HTML file associated with the campaign could transmit information entered by victims directly to Telegram. If users entered sensitive wallet information into the fraudulent process, that functionality could expose recovery phrases, private credentials or other confidential data.

Trezor has warned users not to interact with the malicious email or follow its links.

Previous Customer Data Exposure Raises Phishing Concerns

The latest incident follows a separate customer information exposure involving logistics provider ShipMonk that Trezor disclosed in August.

Information obtained through such an exposure can potentially make subsequent phishing attempts more convincing because attackers may have access to customer details that can be incorporated into targeted communications.

However, no confirmed connection has been established between the ShipMonk exposure and the latest breach involving Trezor's third-party email provider.

The incident nevertheless illustrates how compromising trusted communication infrastructure can make malicious emails significantly harder for recipients and automated security systems to distinguish from genuine company communications.

Trezor users should delete the identified fraudulent alert, avoid clicking links contained in it and never enter a wallet recovery phrase into an online security verification page.


Writer: Marcus Renfield
  
Crypto Market Analyst & Onchain Writer

Marcus Renfield covers cryptocurrency markets with a focus on onchain data, Bitcoin price action, and emerging market narratives. His writing examines how capital flows, network activity, and broader market structure influence short- and medium-term trends.

He aims to provide clear, data-informed analysis for readers seeking a deeper understanding of crypto market dynamics.


Check out other news and articles on Google News

Disclaimer:


The articles published on hoka.news are intended to provide up-to-date information on various topics, including cryptocurrency and technology news. The content on our site is not intended as an invitation to buy, sell, or invest in any assets. We encourage readers to conduct their own research and evaluation before making any investment or financial decisions.
hoka.news is not responsible for any losses or damages that may arise from the use of information provided on this site. Investment decisions should be based on thorough research and advice from qualified financial advisors. Information on hoka.news may change without notice, and we do not guarantee the accuracy or completeness of the content published.