Trezor Reports Third-Party Breach Caused Phishing Emails Sent From Its Own Domain
(22 days ago) · 1 source · Summarized by CryptoBipto
Hardware wallet maker Trezor disclosed that a security breach at a third-party service provider allowed attackers to send phishing emails from Trezor's legitimate email domain. The company has acknowledged the incident and warned users not to act on suspicious emails they may have received.
WHY IT MATTERS
A hardware wallet is a physical device used to store cryptocurrency offline, making it harder for hackers to steal funds remotely. Trezor is one of the most widely used hardware wallet brands. In this case, attackers did not break into Trezor's devices or its core systems — instead, they compromised a separate company that Trezor uses for services like sending emails. Think of it like a locksmith whose office is secure, but the postal service they use to mail keys to customers gets intercepted. Because the phishing emails came from Trezor's real email address, they looked authentic, which could trick users into giving away their "recovery seed phrase" — a secret set of words that acts like a master password for accessing cryptocurrency. If someone shares that phrase, an attacker can drain their wallet. This is a reminder that security in crypto depends not just on the main product but also on every company and tool connected to it.
Read the full analysis with a CryptoBipto membership
Members can read the full analysis of every story, not just the headline.
Get startedSOURCES
- theblock.co
RELATED
Learn the concepts behind this
Clear explanations of the subjects this article touches, with every term defined.