Skip to main content
Back to news
SafetyMajor story — Significance is rated automatically and is not a price signal.

Trezor Reports Third-Party Breach Caused Phishing Emails Sent From Its Own Domain

(22 days ago) · 1 source · Summarized by CryptoBipto

Hardware wallet maker Trezor disclosed that a security breach at a third-party service provider allowed attackers to send phishing emails from Trezor's legitimate email domain. The company has acknowledged the incident and warned users not to act on suspicious emails they may have received.

WHY IT MATTERS

A hardware wallet is a physical device used to store cryptocurrency offline, making it harder for hackers to steal funds remotely. Trezor is one of the most widely used hardware wallet brands. In this case, attackers did not break into Trezor's devices or its core systems — instead, they compromised a separate company that Trezor uses for services like sending emails. Think of it like a locksmith whose office is secure, but the postal service they use to mail keys to customers gets intercepted. Because the phishing emails came from Trezor's real email address, they looked authentic, which could trick users into giving away their "recovery seed phrase" — a secret set of words that acts like a master password for accessing cryptocurrency. If someone shares that phrase, an attacker can drain their wallet. This is a reminder that security in crypto depends not just on the main product but also on every company and tool connected to it.

Trezor, a well-known manufacturer of hardware cryptocurrency wallets, reported that phishing emails were sent to users from its own official domain after a third-party provider it works with was compromised.

Read the full analysis with a CryptoBipto membership

Members can read the full analysis of every story, not just the headline.

Get started

SOURCES

  • theblock.co

RELATED

Hardware WalletsPhishing AttacksSupply Chain SecurityUser Safety