Trezor Breached Again: Scammers Just Got Your Email and They're Already Phishing
For the second time, Trezor has confirmed a data breach, and this time attackers went straight for the marketing platform holding customer contact data, then immediately launched phishing attacks against users.
The hardware wallet maker revealed that a third-party marketing service it uses was compromised by scammers who then weaponized the stolen data to send fraudulent emails impersonating Trezor. If you have ever signed up for Trezor communications, your email address is now in the hands of people who know exactly what kind of asset you are holding.
Why This Breach Hits Different
This is not a theoretical risk. The attackers did not sit on the data. They moved fast, pushing phishing emails to Trezor users almost immediately after gaining access. That speed tells you everything about the level of preparation involved. These are not opportunistic hackers. They targeted a hardware wallet company's user list specifically because every name on it is a confirmed crypto holder.
Trezor's previous breach, disclosed in January 2024, exposed the contact details of roughly 66,000 users after a third-party support portal was compromised. Now a second vendor has been hit. The pattern here is clear: Trezor's own hardware may be secure, but its surrounding vendor ecosystem keeps opening doors that attackers are happy to walk through.
The Phishing Playbook You Need to Know
The attack format is almost always the same. You receive an email that looks like it is from Trezor, warning you of a security issue with your device or account. There is a link. That link takes you to a convincing fake site designed to extract your seed phrase. The moment you enter those 12 or 24 words, your wallet is gone.
Trezor will never ask for your seed phrase. Not by email, not on any website, not ever. If any message, regardless of how official it looks, asks for your recovery phrase, it is a scam. Full stop.
What You Should Do Right Now
First, do not click any links in emails claiming to be from Trezor. Navigate directly to trezor.io by typing it into your browser. Second, if you use the same email for Trezor that you use for exchanges or other crypto services, expect that address to be on active phishing lists. Consider filtering aggressively.
Third, and most critically, your seed phrase should never exist digitally. If it is in a screenshot, a notes app, or a cloud document, move it offline immediately.
The hardware wallet space is only as secure as the weakest link in the vendor chain. Right now, that chain has snapped twice. Stay paranoid, stay skeptical, and treat every Trezor-branded email as hostile until proven otherwise.