Hardware Wallet Maker Trezor Confirms Email Service Breach, Warns Users
Hardware wallet producer Trezor has confirmed a security breach involving a third-party email service provider, resulting in the distribution of phishing emails to its user base. The company issued a warning to customers about fraudulent security alerts designed to steal sensitive information. This incident marks the second security compromise impacting Trezor customers within a month, following a breach at shipping provider ShipMonk that exposed personal details.
The latest attacks leverage the compromised email service to send phishing messages, some appearing to originate from legitimate Trezor domains. These emails falsely claim a hardware flaw could expose users’ recovery phrases, urging recipients to take immediate action. One specific phishing campaign reportedly suggested that 25% of devices were vulnerable.
Wider Crypto Sector Targeted
Trezor’s notification follows similar warnings from other hardware wallet companies, including BitBox. BitBox indicated that multiple Bitcoin-related firms were targeted through a shared newsletter provider, suggesting a broader attack against the cryptocurrency ecosystem. Cyber Daily reported that several hardware crypto wallet providers have alerted users to phishing emails after a third-party incident, highlighting an escalating trend of such attacks across the crypto industry.
The phishing attempts are designed to exploit human trust, rather than directly compromising the hardware wallets themselves. Attackers aim to trick users into revealing their recovery phrases—a sequence of words that grants access to cryptocurrency funds—by creating a false sense of urgency and vulnerability.

The phishing emails falsely claim a hardware flaw could expose users’ recovery phrases, urging recipients to take immediate action.
Market Context and User Vigilance
Hardware wallets are a cornerstone of self-custody in the cryptocurrency market, offering enhanced security by storing private keys offline, away from internet-connected devices. These devices are particularly popular among investors seeking to protect their digital assets from online hacks and exchange failures. However, the recent incidents underscore that even with robust hardware security, the human element and third-party services remain potential vulnerabilities.
For both seasoned crypto enthusiasts and newcomers, these breaches serve as a critical reminder of the importance of vigilance. Users are advised to be extremely cautious of unsolicited emails, especially those requesting recovery phrases or critical personal information, regardless of how legitimate they appear. Trezor has urged its users to disregard any email claiming a security vulnerability or asking for their seed phrase, emphasizing that the company would never ask for this information.

Ongoing Concerns and Recommendations
The repeated nature of these security incidents, particularly the consecutive third-party breaches, raises concerns about the broader supply chain security within the crypto hardware sector. Companies like Trezor rely on a network of external providers for various services, and the security posture of these partners directly impacts the end-user experience.
As the crypto market continues to mature, and more individuals seek secure ways to manage their digital assets, the onus is increasingly on both hardware wallet manufacturers and their users to maintain stringent security practices. Users should verify any suspicious communications directly through official company channels, such as their website or dedicated support lines, rather than clicking links within emails.
Market Snapshot
| Asset | Price | 24h | Market Cap |
|---|---|---|---|
| $78,187 | -1.37% | $1570.2B | |
| $2,474 | -1.49% | $301.9B | |
| $718.66 | -4.79% | $95.7B | |
| $1.38 | -3.69% | $86.9B | |
| $101.59 | -3.11% | $59.6B | |
| $0.0855 | -5.72% | $13.3B | |
| $0.214 | -3.23% | $8.0B |
Live data: CoinGecko — 2026-09-10 07:21 UTC