Crypto Wallet Maker Alerts Customers to Phishing Emails After Vendor Compromise

Trezor has warned its customers that a breach at its third-party email provider allowed attackers to send fraudulent security alerts from a legitimate domain. The phishing emails falsely claim a vulnerability in STM32 microcontrollers could expose wallet seeds to brute-force attacks. The company has taken down the domain and is investigating the incident, which follows a separate data breach affecting over 80,000 customers via its shipping provider.
The current phishing wave follows an August breach at Trezor's logistics vendor, ShipMonk, which compromised personal data for 81,000 customers across multiple nations. That incident originated from a Metabase SQL injection flaw and prompted extortion attempts by the ShinyHunters group.
Trezor has faced prior third-party security failures, notably a January 2024 compromise of its support ticketing system that exposed details for about 66,000 users. The latest attack exploits a legitimate email domain to distribute false alerts regarding STM32 chip vulnerabilities.
This incident could erode trust in hardware wallet security, as users may hesitate to act on legitimate alerts in the future. If victims click the phishing links, they risk exposing their seed phrases, potentially leading to irreversible cryptocurrency theft. The repeated breaches at third-party vendors may also prompt broader scrutiny of supply chain security practices within the crypto industry, affecting how companies handle customer data and communicate urgent warnings.