EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Trezor mailbox leak: Attackers use their own domain name to launch phishing scams

2026-09-10 20:15:11
Bookmark

Trezor claims that a third-party email leak caused attackers to use its official domain name to send phishing emails.

Trezor said that a third-party email service leak allowed attackers to send phishing messages from its hardware wallet manufacturer's own domain name. This is a rare upgrade that deprives users of the ability to identify fake emails, usually by checking the sender's address. The Trezor email leak follows another logistics provider incident that has lasted for months, highlighting that the risks faced by wallet holders now lie largely outside the provider's own infrastructure.

Details of the incident disclosed by Trezor

The core details of the Trezor email leak are troubling: The vulnerability did not appear in Trezor's hardware or core systems, but was located at a third-party email provider. However, this was enough for attackers to weaponize the company's trusted communication channels. According to Unchained, Trezor said the leak allowed attackers to push phishing emails to users.

This malicious activity used a sense of urgency as bait, using "Critical Security Alert: STM32 Entropy Vulnerability" as the subject of the email to prompt recipients to take action. Trezor warns recipients not to click on links within messages. According to unconfirmed reports, the excuse is that the real STM32 entropy flaw requires users to update the device via instructions in the email, but this is itself phishing bait rather than a verified security vulnerability.

Trezor's existing security guidelines are the defenses relevant here: Official support will never ask for mnemonic words (recovery seeds), and users should not enter wallet backups without first initiating a recovery procedure and confirming it on the device. Attackers often covet wallet backup because once a mnemonic phrase is entered on a malicious page, control of the funds is completely transferred to the attacker.

The attacker used Trezor's own domain name to send phishing emails

The difference between this operation and regular cryptocurrency phishing attacks lies in the sender. According to reports, the news did not come from imitation domain names or forged display names, but came directly from Trezor's own domain name. This means that in this case, the usual recommendation to users to double-check addresses provides little protection.

Existing reports do not include samples of messages, specific domain names or technical delivery mechanisms, so the exact path from the provider's leak to the generation of seemingly authenticated messages remains undescribed. Trezor was not the only brand targeted: BitBox warned its customers about similar impersonation activities on the same day, an industry reaction reported by Unchained rather than an independent BitBox statement.

What is unclear about the Trezor email leak

Scope, impact and response

Existing reports fail to determine how many recipients received phishing emails, whether there was financial loss, the identity of the email provider, and the current status of the malicious domain name. These gaps reflect limitations of the available materials rather than evidence that the incident was minor or fully controlled.

Background information comes from another incident disclosed in more detail by Trezor. In its official Frequently Asked Questions (FAQ) updated on September 4, 2026, Trezor stated that 80,689 customers were affected by the leak from logistics provider ShipMonk. Although headlines suggest there is no merger total, the company has announced the number.

The ShipMonk leak was originally released on August 13 and was updated after Trezor learned on September 2 that older order data was also involved. The initial list listed 11,742 fully exposed customers and 1,947 partially exposed customers. The September update added approximately 67,000 U.S. customers whose order data (including names, emails, phone numbers, shipping addresses and order numbers) from November 2019 to August 2021 was retained despite a previous explicit commitment to follow a 90-day retention window and multiple written guarantees of deletion.

Trezor said its own systems were not compromised and its devices remained secure during the ShipMonk incident, but the statement did not extend to subsequent attacks by email providers. There is no evidence that the logistics breach is causally related to current phishing activities, and the claim that ShipMonk data provides a target has not been verified.

This model has become familiar in the industry, and peers such as SafePal have also disclosed the leakage of order information from nearly 40,000 customers. The main thread connecting these events is that the hardware wallet remains secure by design, but the surrounding customer data and communication channels held by logistics and email providers are increasingly becoming more vulnerable targets.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP