BNB $719.20 -4.60%
XRP $1.38 -3.70%
ETH $2,472.59 -1.16%
BTC $78,185.93 -1.23%
BNB $719.20 -4.60%
XRP $1.38 -3.70%
ETH $2,472.59 -1.16%
BTC $78,185.93 -1.23%
BREAKING
Digital Wallet

Trezor Users Targeted by Phishing Attack Using Legitimate Email Infrastructure

Trezor Phishing Attack Bypasses SPF, DKIM, and DMARC as Third-Party Email Provider Falls
Trezor Phishing Attack Bypasses SPF, DKIM, and DMARC as Third-Party Email Provider Falls

Community Trust ScoreVerified

86%
Real
Verified14 votes
Updated 29 minutes ago

Trezor got hit. Hard. A sophisticated phishing campaign reached hardware wallet users after attackers broke into the company’s third-party email provider, sending fraudulent messages that looked, for all practical purposes, completely real.

The emails weren’t just convincing — they were technically authenticated. They passed SPF, DKIM, and DMARC checks, which basically means Gmail displayed them as “signed-by: trezor.io.” That’s the kind of thing that makes even security-savvy users pause. If your email client vouches for the sender, you’re probably not going to second-guess it. And that’s exactly what the attackers counted on.

Trezor took down the affected domain fast.

Advertisement

How the Attack Actually Worked

The phishing emails were sent using infrastructure that was authorized to send messages on Trezor’s behalf. That’s the key detail here. It wasn’t a spoofed address or a lookalike domain — the attackers got inside legitimate sending infrastructure and used it. The result was an email that cleared every standard authentication hurdle most email providers rely on.

The message itself pushed urgency hard. It claimed Trezor devices had a critical entropy vulnerability — a scary-sounding technical flaw — and pushed users to complete a fake security verification process immediately. The timing was deliberate too, probably. A similar vulnerability scare had recently hit Coldcard wallet users, so the crypto community was already primed to panic over that kind of alert. Attackers exploited that existing anxiety.

One detail that surfaced through community investigators: the phishing scheme included an “offline” HTML file. When users interacted with it and entered data, that information was sent directly to Telegram. Clean, hard to trace, and pretty effective at extracting sensitive details from people who thought they were protecting their wallets.

Trezor hasn’t said how many customers received the phishing message. No number. No estimate. Unclear when or if they’ll disclose that.

Brevo, BitBox, and a Possible Wider Breach

Community investigators pointed fingers at Brevo, an email marketing provider, as the likely source of the breach. Trezor hasn’t confirmed that. The company’s official position is that the investigation is ongoing and the identity of the compromised provider hasn’t been publicly named.

But here’s what makes this messier: users of BitBox and CoinTracking also reported getting suspicious emails around the same time. That overlap is hard to ignore. If multiple crypto services share an email infrastructure provider — and many do, because these platforms are widely used across the industry — a single breach at that provider could explain the simultaneous wave of phishing attempts hitting different user bases at once.

That’s not confirmed. But it’s probably the most logical explanation floating around right now.

Trezor also dealt with a separate incident back in August, involving ShipMonk, a shipping provider. That breach exposed customer data. The company was clear that there’s no confirmed link between the ShipMonk exposure and the current email provider breach. Two different third-party vendors, two different types of data, two different incidents. Still, it’s not a great look for a hardware security company to have recurring third-party problems in quick succession.

What Trezor Is Doing Now

The company is investigating how attackers gained access to the authorized email infrastructure tied to its legitimate domain. It’s focused on understanding the exact method used and reinforcing security protocols to stop something like this from happening again. Beyond that, details are thin.

Trezor urged users to stay cautious with unexpected communications, especially anything requesting sensitive information or pushing security alerts. Don’t click links. Verify independently. That’s the guidance, and it’s worth repeating because the emails in this campaign were genuinely difficult to distinguish from real ones.

The broader problem isn’t really Trezor-specific. Hardware wallet makers, exchanges, and crypto platforms of all sizes rely on third-party vendors for email, shipping, customer support, and a dozen other functions. Each of those vendors is a potential attack surface. And attackers know it. Targeting a trusted vendor that serves multiple crypto companies is efficient — one breach, multiple victim pools.

The sophistication here matters. Passing SPF, DKIM, and DMARC isn’t trivial. It means the attackers didn’t just send a sketchy email from a random server. They got inside something real, something trusted, and used it as a weapon. The offline HTML file routing data to Telegram added another layer — it’s not the kind of setup you throw together overnight.

Trezor’s investigation is ongoing. No attackers identified. No provider confirmed. No user count disclosed.

Frequently Asked Questions

What did the Trezor phishing email claim?

The email falsely told users their Trezor devices had a critical entropy vulnerability and directed them to complete a fake security verification process to resolve it.

Which email authentication checks did the phishing email pass?

The phishing emails passed SPF, DKIM, and DMARC checks, causing Gmail to display them as “signed-by: trezor.io” — making them appear fully legitimate.

Were other crypto platforms affected beyond Trezor?

Users of BitBox and CoinTracking also reported receiving suspicious emails around the same time, pointing to a possible shared compromised email infrastructure, though no common source has been officially confirmed.

Why It Matters

This phishing attack highlights a significant vulnerability in the crypto space, where even established security measures like SPF, DKIM, and DMARC can be circumvented. As users increasingly rely on hardware wallets for asset security, incidents like this may erode trust in both individual wallet providers and the broader cryptocurrency ecosystem, potentially impacting user adoption and market stability. Moreover, this event underscores the necessity for enhanced security protocols and user education in the face of evolving cyber threats.

Community Trust IndexModerate Confidence
86%
Real
Real86%14%Fake
14 community signals

Maheen Hernandez

A finance graduate, Maheen Hernandez has been drawn to cryptocurrencies ever since Bitcoin first gained mainstream attention. She covers the latest developments in blockchain technology, DeFi protocols, and regulatory frameworks for The Currency Analytics.

Advertisement

Related Stories