uMaHF0G5M1jYL9t88qHEEkQggU6GJ5wTZlhvItt7
Bookmark

Trezor Warns of Phishing Emails Sent From Legitimate Domain

Trezor warns users after hackers breach its email provider and send fake security emails targeting recovery phrases through a legitimate domain.

Trezor has warned customers about a phishing campaign following a breach at one of its email service providers, with attackers sending fraudulent security notices from a legitimate Trezor domain.

According to Coin Bureau, the emails claim that a “Critical Security Alert: STM32 Entropy Vulnerability” could put users’ recovery phrases at risk. Trezor has confirmed that the alert is fraudulent and said the domain used in the campaign has been taken down.

Fake Trezor Security Alert Targets Recovery Phrases

The campaign is notable because the phishing messages reportedly originated through legitimate Trezor-associated email infrastructure. That can markets malicious communications appear more credible than conventional spoofed emails and increase the risk that users will interact with embedded links or disclose sensitive wallet information.

Trezor has made clear that there is no genuine security alert concerning an “STM32 Entropy Vulnerability” requiring users to provide or enter their recovery phrases. Users should therefore avoid links contained in unsolicited security emails and verify any warning directly through Trezor’s official communication channels.

The incident adds to a series of security issues financial involving third-party vendors connected to Trezor. Coin Bureau described it as the company’s third vendor breach in four weeks, following an incident involving Trezor’s support portal that exposed information associated with 66,000 users.

ShipMonk Breach Exposed Customer Addresses

The latest incident also follows a breach involving ShipMonk, a shipping partner used by Trezor. According to the information cited by Coin Bureau, the incident exposed the home addresses of more than 80,000 customers.

The sequence of incidents highlights a broader cybersecurity challenge for cryptocurrency companies that rely on external providers for customer support, logistics and communications. Even when core wallet systems are not directly compromised, information obtained through vendors can potentially be used to construct more convincing phishing campaigns.

For hardware-wallet users, the immediate security priority remains protecting the recovery phrase. Legitimate support personnel should not require users to disclose their recovery phrase, and any request to enter it into a website or provide it by email should be treated as suspicious.

Trezor’s next step will be to investigate the email-provider compromise and determine whether additional customer information or communications infrastructure was affected.


Writer: Victoria Hale  
Technology & Blockchain Writer

Victoria Hale writes about blockchain technology, digital infrastructure, and the intersection of emerging technologies with finance. Her articles explore how new protocols and systems are shaping the evolving digital economy.

She prioritises clarity and accuracy when explaining technical developments to a general audience.

Check out other news and articles on Google News

Disclaimer:

The articles on HOKA.NEWS are here to keep you updated on the latest buzz in crypto, tech, and beyond—but they’re not financial advice. We’re sharing info, trends, and insights, not telling you to buy, sell, or invest. Always do your own homework before making any money moves.

HOKA.NEWS isn’t responsible for any losses, gains, or chaos that might happen if you act on what you read here. Investment decisions should come from your own research—and, ideally, guidance from a qualified financial advisor. Remember:  crypto and tech move fast, info changes in a blink, and while we aim for accuracy, we can’t promise it’s 100% complete or up-to-date.

Stay curious, stay safe, and enjoy the ride! hoka.news