Phishing Campaign Exploits Trezor’s Third-Party Email Provider Breach
Trezor, a leading hardware wallet manufacturer, has revealed that a third-party email service it partners with was compromised by hackers. Malicious actors used the breached email system to send phishing emails impersonating security alerts about a critical vulnerability in Trezor's STM32 chip. These emails urged users to click on fraudulent links, attempting to extract sensitive information or cause harm. This marks the third supply chain-related security incident Trezor has disclosed within a month.
Trezor responded by shutting down the malicious domain used in the phishing campaign and is conducting an in-depth investigation into how attackers exploited the legitimate domain to distribute these emails. Importantly, Trezor confirmed that no hardware wallets, private keys, or recovery seeds were directly impacted by this breach.
Recurring Supply Chain Security Breaches Raise User Concerns
Earlier this year, on August 10th, Trezor’s fulfillment partner ShipMonk experienced a data leak that exposed personal information—including names, phone numbers, and addresses—of over 80,000 customers. Following that incident, users reported receiving scam calls and counterfeit letters, indicating heightened phishing and fraud risks.
Beyond this, Trezor has previously encountered security challenges; in 2024, a breach of its customer support portal compromised data on approximately 66,000 users. Similarly, competitor SafePal recently suffered a leak involving close to 40,000 clients' data. While none of these breaches have affected the actual hardware security or private keys, they highlight vulnerabilities in data protection within hardware wallet ecosystems and their third-party partners.
Analysis of the Phishing Email: The STM32 Chip Entropy Vulnerability Claim
The phishing emails claimed to warn users about an “STM32 entropy vulnerability.” STM32 microchips are integral components in Trezor devices responsible for generating cryptographic randomness crucial for recovery phrase security. The message suggested that this flaw could undermine the randomness quality used in generating recovery seeds, potentially endangering wallet security.
Given users’ strong focus on the integrity of recovery phrases, any purported weaknesses in entropy generation carry significant weight and can evoke anxiety, which malicious actors seek to exploit to induce clicks on phishing links.
Trezor’s Security Measures and User Advisory
In response, Trezor has pledged to enhance security reviews throughout its supply chain to prevent future exploitation of partner vulnerabilities. The company emphasizes that wallet security fundamentally depends on safeguarding private keys and recovery seeds. It cautions users against trusting unsolicited emails asking them to verify security flaws via suspicious links.
This incident underscores that while hardware wallet devices themselves may maintain robust security, the security posture of affiliated service providers remains critical. Users should remain vigilant against social engineering attempts and potential scams while interacting within the hardware wallet ecosystem.