Current outcome
Trezor confirmed that a breach at its third-party email service provider exposed the contact data of hundreds of thousands of crypto owners, who are now being targeted by phishing and social-engineering campaigns. Trezor warned that an email titled "Critical Security Alert: STM32 Entropy Vulnerability" did not come from the company, said it had taken down the malicious domain, and is investigating how attackers obtained access to a legitimate Trezor domain. Although no private keys or funds were directly compromised, the leaked contact data gives attackers the raw material for convincing, personalized phishing aimed at a large population of hardware wallet users. It is also Trezor's second vendor-related incident in quick succession, which puts third-party supply-chain risk for self-custody providers under renewed scrutiny. The phishing messages gained credibility by being sent from a legitimate Trezor domain, meaning standard sender-authentication checks would not flag them. The exposed dataset includes names, email addresses and phone numbers, and in August Trezor disclosed a separate breach at its shipping and logistics provider ShipMonk that leaked order data such as full names, shipping addresses, emails and phone numbers — datasets that can be combined to make impersonation attacks far more persuasive.
Progress timeline
1 material updates- #01
Trezor email provider breach exposes hundreds of thousands of crypto owners to scammers
Trezor confirmed that a breach at its third-party email service provider exposed the contact data of hundreds of thousands of crypto owners, who are now being targeted by phishing and social-engineering campaigns. Trezor warned that an email titled "Critical Security Alert: STM32 Entropy Vulnerability" did not come from the company, said it had taken down the malicious domain, and is investigating how attackers obtained access to a legitimate Trezor domain. Although no private keys or funds were directly compromised, the leaked contact data gives attackers the raw material for convincing, personalized phishing aimed at a large population of hardware wallet users. It is also Trezor's second vendor-related incident in quick succession, which puts third-party supply-chain risk for self-custody providers under renewed scrutiny. The phishing messages gained credibility by being sent from a legitimate Trezor domain, meaning standard sender-authentication checks would not flag them. The exposed dataset includes names, email addresses and phone numbers, and in August Trezor disclosed a separate breach at its shipping and logistics provider ShipMonk that leaked order data such as full names, shipping addresses, emails and phone numbers — datasets that can be combined to make impersonation attacks far more persuasive.
Source evidence: techcrunch.com