Trezor announced on Wednesday that a breach at its third-party email provider enabled attackers to distribute phishing emails disguised as critical security warnings. The fraudulent messages claimed an STM32 hardware flaw weakened recovery phrases on some devices, falsely stating the defect affected one in four units. Trezor confirmed the alert was not from them, took down the malicious domain, and is investigating how access to its legitimate domain was gained.
Security researchers indicated the campaign may extend beyond Trezor, with similar emails targeting BitBox users suggesting a broader compromise of hardware-wallet email providers. Casa CEO Nick Neuman and Chief Security Officer Jameson Lopp warned that malicious emails claiming bad random number generators were being sent without appearing spoofed. This incident follows recent breaches involving Coldcard exploits and ShipMonk data leaks that exposed customer information for sophisticated phishing attempts.
This development highlights the persistent vulnerability of supply-chain infrastructure in the crypto sector, where trust is often placed in third-party communication channels rather than just the device itself. By leveraging a compromised email provider, attackers bypassed traditional spoofing detection mechanisms, making the phishing attempt appear legitimate through valid DKIM, SPF, and DMARC records. This underscores that operational risk extends beyond hardware manufacturing to the digital delivery systems used for user notifications.
The convergence of threats against multiple hardware wallet brands suggests coordinated efforts to exploit market anxiety following high-profile losses like the Coldcard incident. For institutional adoption, this reinforces the need for rigorous verification protocols that do not rely solely on email authenticity. Stakeholders must watch for further disclosures regarding the specific email service provider involved and whether other custodial or self-custody solutions have experienced similar breaches in their notification pipelines.


