Trezor Announces Latest Security Breach: Important Information for Customers
Trezor’s third vendor breach in four weeks has exposed customer contact information to phishing attacks, highlighting how hardware wallet security depends critically on the integrity of third-party service providers. Users face immediate risk from convincing emails impersonating legitimate security alerts, despite the devices themselves remaining secure.
- Trezor’s email provider was breached, enabling attackers to send phishing emails posing as critical chip security alerts to customers.
- More than 80,000 Trezor customers had names, phone numbers, and home addresses exposed in the August ShipMonk logistics partner breach.
- BitBox and other Bitcoin hardware wallet makers were targeted by similar phishing campaigns, suggesting a coordinated attack on shared newsletter infrastructure.
- 80,000+ Trezor customers exposed in ShipMonk breach with contact information leaked
- 3 vendor security failures affecting Trezor in a four-week period
- 66,000 Trezor users warned after support portal breach in 2024
- 40,000 SafePal records leaked last month, comparable to hardware wallet exposure
Trezor disclosed that attackers compromised its third-party email provider and used the access to distribute phishing emails to customers, marking the third vendor failure to impact the hardware wallet maker within four weeks. The fraudulent messages impersonated critical security alerts regarding an STM32 entropy vulnerability, referencing the actual chip family used in Trezor devices. Trezor stated it took down the malicious domain and confirmed that private keys, wallets, and recovery backups were never exposed, though the breach underscores how customer data held by service providers remains vulnerable even when core device security remains intact.
ShipMonk Breach exposed over 80,000 customer records
The current phishing campaign followed an August 10 breach at ShipMonk, the logistics partner responsible for shipping Trezor hardware to customers. By September 4, ShipMonk had confirmed exposure of customer names, phone numbers, and home addresses affecting more than 80,000 Trezor users. The leaked contact details created a foundation for convincing phishing attempts, as attackers could reference real customer information while spoofing legitimate Trezor communications.
Customers have reported receiving scam calls and printed letters following the ShipMonk incident, indicating attackers actively weaponized the leaked data beyond email. This pattern reflects a wider vulnerability in the hardware wallet supply chain, where shipping partners, support systems, and marketing platforms hold sensitive customer information outside the direct control of device manufacturers.
The concentration of breaches in a short timeframe suggests either systematic targeting of Trezor infrastructure or a broader campaign against cryptocurrency security providers. Hardware wallet companies occupy a unique position as both attractive targets for attackers seeking customer information and trusted entities whose domains and communications carry significant weight with security-conscious users.
The STM32 entropy vulnerability Phishing lure exploited technical credibility
The fake security alert specifically cited an STM32 entropy vulnerability, a technically plausible threat designed to trigger urgency in targeted users. STM32 chips power Trezor devices, and entropy refers to the randomness that generates recovery phrases controlling access to funds. Weak entropy would represent a genuine cryptographic failure, lending credibility to the phishing message for security-conscious wallet owners unfamiliar with Trezor’s actual security architecture.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
Trezor team, statement
The effectiveness of the STM32 lure reflects how hardware wallet users face a trust dilemma: legitimate security alerts require urgent attention, but phishing campaigns exploit that same urgency. Users who clicked links in the fraudulent emails risked entering recovery phrases or device credentials on attacker-controlled pages.
This technique of combining publicly available technical details with leaked customer information represents an advanced social engineering approach. The phishing emails appeared to come from Trezor’s actual infrastructure while referencing specific device components, making them considerably more convincing than generic cryptocurrency scams.
BitBox and multiple Bitcoin firms hit by coordinated newsletter provider Attack
BitBox, a Swiss hardware wallet maker, reported a similar phishing campaign sent to its newsletter subscribers on September 9, suggesting the attacks were not isolated to Trezor. BitBox stated that its newsletter provider was likely compromised and that multiple Bitcoin companies using shared newsletter infrastructure were targeted simultaneously. The coordinated nature of the attacks indicates attackers targeted the email and marketing platforms serving the hardware wallet industry rather than individual companies.
This pattern exposes a systemic risk in hardware wallet vendor ecosystems. Even as manufacturers harden device firmware and cryptographic implementations, centralized service providers like shipping platforms, email services, and newsletter distributors remain attractive targets for attackers seeking customer contact information and sender domain access.
The broader cryptocurrency industry has experienced similar supply chain attacks. Other hardware wallet manufacturers and cryptocurrency exchanges have faced comparable breaches of vendor infrastructure, suggesting that attackers view third-party platforms as higher-value targets than attempting to compromise device firmware directly.
Immediate protective steps for Trezor and Hardware Wallet users
Users should ignore unexpected emails citing STM32 or entropy issues and never enter recovery phrases or passphrases into any website, regardless of the sender domain.
Trezor advised customers to verify security alerts by checking trezor.io directly or consulting the verified Trezor account on X, bypassing email entirely. Physical mail and unsolicited phone calls should be treated as hostile until independently verified through official channels. Any user who entered a backup recovery phrase on a linked page during the phishing campaign should immediately move funds to a newly generated wallet.
Industry observers recommend that hardware wallet users maintain healthy skepticism toward all unsolicited communications, regardless of apparent sender credibility. This approach reflects the unfortunate reality that verified vendor domains and email addresses can be compromised or spoofed effectively, making out-of-band verification essential for security-critical communications.
Trezor has not publicly detailed whether it plans to change its third-party vendor selection process or implement additional controls over email provider access following three breaches in four weeks. The company faces pressure to strengthen oversight of service providers handling customer data, particularly those with direct access to communications infrastructure. Users remain dependent on verifying all security communications through independent channels rather than trusting email from established domain names, a burden that highlights the need for stronger vendor accountability across the hardware wallet industry.
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
