HomeMarket News

Trezor Email Provider Breach Lets Phishing Attack Pass Security Checks

Trezor Email Provider Breach Lets Phishing Attack Pass Security Checks

Summary

  • Trezor warned customers that attackers had compromised its third-party email provider and distributed convincing phishing alerts through the company’s authorized infrastructure.
  • Fraudulent messages passed SPF, DKIM, and DMARC checks, making them harder for recipients and automated spam filters to identify quickly
  • Attackers promoted a fake entropy vulnerability, while Trezor found no confirmed link to its earlier disclosed ShipMonk customer data exposure.

 


Trezor has warned customers about a highly sophisticated phishing campaign involving its compromised third-party email provider. Attackers used trusted company infrastructure to distribute security alerts that appeared to originate from the hardware wallet manufacturer.


According to Trezor, the malicious email carried the title “Critical Security Alert: STM32 Entropy Vulnerability.” “Our third-party email provider has been breached,” Trezor warned, urging customers not to open links inside the message.


Trezor removed the affected domain and began investigating how the attackers accessed infrastructure connected to its legitimate online systems. However, the company has not revealed how many customers received the message or identified the affected provider.


The campaign created considerable security risks because the emails lacked many warning signs normally associated with common phishing attempts. Screenshots showed “Trezor Security” as the sender, alongside the legitimate-looking address [email protected].


Additionally, Gmail identified mailing.trezor.io as the delivery source and trezor.io as the domain signing the messages. Emails reportedly passed SPF, DKIM, and DMARC checks, which verify whether messages originate from authorized sending infrastructure. Consequently, recipients had fewer reasons to question the alerts, while automated spam filters were less likely to block them.


Also Read: Solana App Revenue Doubles Robinhood Chain as SOL Holds Above $100


Attackers Use Fabricated Vulnerability to Target Wallet Owners

The fraudulent warning claimed Trezor devices contained an entropy vulnerability that could compromise the randomness protecting users’ cryptographic information. Attackers used that claim to create urgency and direct customers toward a fraudulent security verification process.


One Trezor forum user reported that an offline HTML file could transmit information entered by victims directly to Telegram. Such functionality could expose recovery phrases, private credentials, or sensitive information submitted during the fraudulent verification process.


Trezor previously disclosed a separate customer information exposure involving logistics provider ShipMonk in August. That incident could increase phishing risks because leaked customer details help criminals create personalized and believable messages.


However, investigators have found no confirmed link between the ShipMonk exposure and this email provider breach. This campaign demonstrates that authenticated emails can carry malicious material when criminals compromise trusted communication infrastructure. Trezor users should delete the identified alert, avoid its links, and never submit wallet recovery phrases through online verification pages.


Also Read: Litecoin to Monero: A No-Registration Swap Guide