Hardware wallet provider Trezor has disclosed a security incident involving its email service provider that resulted in fraudulent communications being sent to users. The company confirmed that attackers gained access to the third-party email platform used for distributing official communications to customers Decrypt.
The breach enabled the distribution of counterfeit security alerts that falsely claimed a hardware flaw could expose users' recovery phrases. These fraudulent messages were designed to appear as legitimate correspondence from Trezor, leveraging the compromised infrastructure to deceive recipients about the security status of their devices Decrypt.
The incident highlights persistent supply chain vulnerabilities in cryptocurrency security infrastructure, where trusted communication channels become vectors for social engineering attacks. Third-party email providers represent critical dependencies for hardware wallet manufacturers, as these services handle sensitive customer contact information and serve as primary channels for security notifications.
Recovery phrases constitute the master keys to cryptocurrency holdings stored in hardware wallets. Any communication suggesting these phrases may be compromised represents a severe threat vector, as users might be manipulated into revealing these credentials or transferring funds under false pretenses of protective action.
Trezor has not disclosed which specific email provider was affected, the duration of the unauthorized access, or the number of users who received the fraudulent communications. The company maintains that its hardware devices themselves were not compromised and that no actual vulnerability exists in the physical security architecture of its wallets Decrypt.
This incident follows a pattern of sophisticated targeting of cryptocurrency hardware wallet users through compromised communication channels. Attackers increasingly focus on auxiliary infrastructure rather than direct device exploitation, recognizing that social engineering through trusted channels often proves more effective than technical attacks against hardened hardware security modules.
Users receiving security communications from hardware wallet providers should verify alerts through multiple independent channels before taking any action affecting their holdings. Direct verification through official websites, avoiding links in unsolicited emails, and consulting community-verified information sources remain essential practices for mitigating risks from compromised communication infrastructure.