# Trezor Users Are Being Phished Right Now — and the Attack Came Through the Back Door


Hardware wallet owners believe they've already solved the security problem. They bought the device, wrote down the seed phrase, air-gapped their private keys from the internet. Then an email lands in their inbox from what looks like Trezor, and suddenly all of that discipline is one click away from evaporating.


That's the situation Trezor users faced this week. The company confirmed that threat actors breached its third-party email provider and are now using the stolen customer contact data to run targeted phishing campaigns against the people most motivated to fall for them: people with real money in crypto.


## The Breach You Didn't Hear About First


The initial compromise wasn't Trezor's systems. It was the email infrastructure they trusted to reach their customers — a vendor whose name most Trezor users never knew, and whose security posture they had no visibility into. Trezor's warning on Wednesday confirmed that threat actors accessed the provider, harvested customer email addresses, and are now impersonating the company in follow-on attacks.


The phishing messages, as is standard for crypto targeting, almost certainly aim at one thing: seed phrases. Hardware wallet security is architecturally sound. The seed phrase — typically 12 or 24 words — is the actual vulnerability, and it lives in the user's head or on a piece of paper. If an attacker can convince someone to type those words into a fake recovery portal, the wallet hardware is irrelevant. Funds transfer out in minutes. There is no fraud department to call.


Trezor has advised users not to enter their recovery seed anywhere online under any circumstances, which is correct and also the kind of advice that sounds obvious until you're staring at a convincing email with a countdown timer.


## Third-Party Risk, Again


This is not Trezor's first rodeo with this particular attack pattern. In April 2022, Mailchimp — then widely used for crypto company newsletters — was breached by an insider. The attackers specifically targeted crypto-sector clients, exfiltrating audience data from roughly 100 accounts. Trezor was among them. A phishing wave followed almost immediately.


That 2022 incident should have been a watershed moment for how crypto companies think about their email vendors. The lesson wasn't "don't use Mailchimp" — it was that your customer email list is a high-value target sitting in a third party's database, and that third party's security posture is now your threat surface whether you like it or not.


Evidently the lesson didn't fully land across the industry, because here we are again, different provider, same playbook.


Third-party email platforms are soft targets for a specific reason: they aggregate enormous customer databases across thousands of clients, they require broad API access to function, and their own security teams are protecting an asset — customer data — that belongs to someone else. The incentive structure is misaligned. The breach costs land on the companies whose customers got exposed, not primarily on the email provider.


## What the Attacker Knows About You


The real danger isn't just that someone has your email address. It's what that email address tells an attacker about you.


If you're in a Trezor customer list, you are:

  • Almost certainly a cryptocurrency holder, not a casual observer
  • Technically sophisticated enough to purchase hardware security — which paradoxically can make you overconfident
  • Likely to have a meaningful balance, because you bothered with a hardware wallet
  • Familiar enough with Trezor's brand to respond to communications from them

  • That's a near-perfect targeting profile. These aren't the spray-and-pray phishing campaigns chasing anyone with an email address. This is a rifle shot at a population the attacker already knows has something worth stealing.


    The messages will look legitimate. Trezor's branding is well-known and easy to replicate. The urgency will be manufactured — a fake firmware vulnerability, a supposed security incident requiring immediate seed phrase verification, an account suspension. The goal is to create a situation where clicking feels safer than not clicking.


    ## What Defenders Need to Do Right Now


    If you're a Trezor user, the actions are simple and non-negotiable:


    Your seed phrase never goes online. Not into a Trezor portal, not into a "secure verification" page, not into anything reachable via a browser. If any message — email, SMS, push notification — asks for your seed phrase, it's a phishing attempt. Full stop.


    Verify through official channels only. Trezor's actual domain is trezor.io. If you receive a security notice, type that address manually. Don't click links in emails.


    Check your email settings. If you've used Trezor's newsletter or customer communications, assume your email address is in circulation. Consider a dedicated email address for hardware wallet registrations going forward — compartmentalization that limits the blast radius when this happens again.


    For companies in the crypto and fintech space, the vendor question is harder but more important. Your email provider has your customer list. That list is a target. Questions worth asking before the breach notification arrives: what data does the provider store and for how long? What does their incident response look like? Who has API access to your audience? Is your customer list segmented, or is it one breach away from full exposure?


    ---


    ## HackWire Analysis


    The Trezor situation fits a pattern that the security industry keeps rediscovering the hard way: the attackers go where the data is, not where the security is.


    Trezor's actual product — the hardware wallet — is well-designed. The seed phrase never touches an internet-connected device during normal operation. From a pure hardware security standpoint, it's hard to fault. But security is a system, and the weakest point in the system right now isn't the wallet. It's the marketing database.


    What's getting missed in most coverage is the economic logic driving this. Crypto wallet owners are among the highest-value phishing targets on earth. A successful seed phrase harvest from even a handful of users can return more than a ransomware operation targeting a mid-sized company. The ROI on this kind of targeted campaign — using a stolen customer list from a breach that cost the attacker little or nothing — is extraordinary.


    The broader trend here is vendor-chain phishing: instead of attacking the target directly, attackers compromise the infrastructure the target trusts to communicate with its customers. We saw this with Mailchimp in 2022, with Klaviyo in 2022 (same incident wave), and with various CRM providers since. The pattern is durable because most companies accept third-party email vendor risk as a cost of doing business without fully accounting for what that risk means when the vendor is breached.


    The companies that handle this best are starting to treat their marketing databases with the same classification rigor as customer PII — because that's what it is. Minimum data retention, regular purges of lapsed subscribers, segmented lists that limit exposure per breach. These aren't radical ideas. They're just not common practice yet.


    Until they are, expect this playbook to keep running. The attacker doesn't need to break the safe — they just need to trick you into opening it yourself.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)