Trezor Users Targeted by Terrifying Phishing Attack After Third-Party Breach

CN
U.today
Follow
1 hour ago

Trezor users have been targeted by an unusually convincing phishing campaign after attackers compromised a third-party email provider used by the hardware wallet manufacturer. 


The company confirmed late Wednesday that a fraudulent email titled "Critical Security Alert: STM32 Entropy Vulnerability" had been distributed to users.


"Our third-party e-mail provider has been breached," Trezor said. "Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it’s a phishing attempt. Do not click on any link."


HOT Stories Trezor Users Targeted by Terrifying Phishing Attack After Third-Party Breach XRP, Stellar (XLM), Dogecoin (DOGE) and Near Protocol (NEAR) Price Analysis for September 10: Will Market Reclaim Momentum?

Trezor added that it had taken down the affected domain and was investigating how the attackers managed to gain access to infrastructure that is linked to the legitimate domain.


The company has not publicly disclosed how many customers received the phishing message. 


Not a typical phishing email 


This incident is particularly terrifying because it does not involve misspelled or obviously fraudulent addresses.


In fact, the malicious messages were delivered via infrastructure authorized to send email on Trezor's behalf. This makes it way harder for both users and automated spam filters to identify them. 


A screenshot circulating following the attack shows the email identifying its sender as "Trezor Security" with the address help@trezor.io.


card


More importantly, Gmail displayed "mailed-by: mailing.trezor.io" and "signed-by: trezor.io."


The fraudulent messages passed SPF, DKIM, and DMARC checks. This helps explain why recipients could see "signed-by: trezor.io" in Gmail and why the messages were less likely to be relegated to spam.


Really brutal. The phishing email is written quite convincingly, and it comes from the official Trezor domain.

At least tens of millions will be lost; hopefully not hundreds of millions. Insane f*ckup from Trezor. https://t.co/GBVcqBEJVh pic.twitter.com/4xw8QM8bvi

— FatMan (@FatManTerra) September 9, 2026

Fake vulnerability warning 


The attackers attempted to create urgency by claiming that Trezor devices had a critical entropy vulnerability (compromised randomness). They were trying to capitalize on the panic stemming from the nightmare that devastated Coldcard wallet owners earlier this year. 


Unfortunate email recipients were then pushed to go through what looked like a security verification process. 


One Trezor forum user said an "offline" HTML file was capable of transmitting entered information to Telegram.


Other companies reportedly affected 


There have been other suspicious emails targeting customers of BitBox and cryptocurrency portfolio service CoinTracking.


Some community investigators have pointed to email marketing provider Brevo as the common infrastructure behind the incidents.


Trezor itself has not identified the email provider that has been compromised. 


A similar incident  


As reported by U.Today, the company disclosed a separate incident in August . The incident, which involved shipping provider ShipMonk, exposed customer information and could increase the risk of targeted phishing.


There is currently no confirmed evidence that the ShipMonk exposure and Wednesday's email-provider compromise were caused by the same attackers.


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink