Bitcoin hardware wallet manufacturer Trezor announced that its third-party email provider had been compromised in a cyberattack and that attackers were using the infrastructure to send fake security alerts to users.
The company warned users that emails particularly carrying the subject “Critical Security Alert: STM32 Entropy Vulnerability” were not created by Trezor and constituted a phishing attempt.
Trezor also announced that it had disabled the domain used in the attack and was investigating how the attackers gained access to the email infrastructure.
What Did the Fake Email Claim?
The fraudulent message claimed that a critical hardware security vulnerability had been discovered in the STM32 microcontrollers used in Trezor devices.
The email alleged that the vulnerability could weaken the level of randomness used when generating recovery phrases on certain devices and potentially put users’ assets at risk.
The apparent objective was to create anxiety among users and direct them toward fraudulent links.
Trezor stated that the email was not legitimate and urged users not to click on any links.
The Real Risk Is Phishing, Not the Hardware
The critical point here is that the incident does not mean Trezor devices themselves were directly compromised.
The fact that the attack centered on the company’s third-party email infrastructure indicates that the primary threat to users is phishing and social engineering.
The attackers’ objective is to create the impression that a genuine security problem exists, persuade users to take action, and ultimately obtain their recovery phrases.
If a recovery phrase for a crypto wallet is compromised, attackers can control the user’s assets without physically accessing the device itself.
BitBox Users Were Also Targeted
There are also indications that the incident may not have been limited to Trezor.
Nick Neuman, co-founder and CEO of Casa, stated that BitBox users had also received messages with similar content.
Bitcoin security researcher Jameson Lopp pointed to the possibility that the email providers used by Trezor and BitBox may have been targeted by attackers.
If this possibility proves correct, it could indicate that the attack was not simply a campaign against a single hardware wallet manufacturer, but rather a broader attack targeting the email and marketing infrastructure used by crypto companies.
Coldcard Vulnerability Turned Into an Opportunity
The timing of the attack is also noteworthy.
Following the recent emergence of security vulnerabilities affecting Coldcard hardware wallets, concerns among crypto users regarding hardware wallet security had increased.
Attackers appear to have exploited this environment by turning a genuine security discussion into a fraudulent warning.
The basic method is quite simple: reference a real security issue, create a sense of urgency, and direct the user toward a fraudulent link.
Trezor Had Previously Warned of a Data Breach
This is not the only security risk Trezor has faced.
In August, the company reported that a security breach at logistics service provider ShipMonk had exposed data belonging to 80,689 customers.
The exposed information reportedly included names, email addresses, phone numbers, and shipping addresses.
While this information alone cannot be used to take control of a wallet, it could make it easier for attackers to create more targeted and convincing phishing messages.
What Could Be the Biggest Mistake Users Make?
The most important security rule for hardware wallet users remains unchanged:
A recovery phrase should never be provided to a website, email form, or another person under any circumstances.
The fact that a message appears to come from an official company address is not sufficient on its own. Attackers can compromise third-party email systems and create highly convincing messages.
Messages that ask users to re-enter or verify their recovery phrase, or to recover their wallet through a link, should be treated as serious warning signs.
A New Front in Crypto Security
The Trezor incident demonstrates that security risks in the crypto industry are not limited to blockchain or hardware vulnerabilities.
Email services, logistics companies, and other third-party service providers are also becoming targets for attackers.
As a result, focusing security efforts solely on the wallet device may no longer be sufficient. Security across the entire chain — from systems storing user data to companies’ communication infrastructure — has become critical.
The Trezor incident also highlights an important reality: in attacks targeting crypto users, creating fear and a sense of urgency has become just as powerful a weapon as a technical vulnerability.
