Trezor Users Are Getting Phishing Emails From Trezor's Own Domain: Here's What You Need to Know
Phishing emails are landing in Trezor customers' inboxes sent from Trezor's own legitimate email domain, and the company says a third-party security breach is to blame.
This is not a spoofed sender address. This is not a look-alike domain. Attackers are sending emails that appear completely authentic because they are originating from infrastructure tied to a compromised third-party vendor with access to Trezor's communications systems. That distinction matters enormously, because every standard piece of advice about checking sender addresses becomes useless overnight.
The Breach Behind the Breach
This attack does not exist in isolation. It follows a separate security incident last month involving ShipMonk, a shipping provider used by Trezor. That breach exposed personal information belonging to Trezor customers, including names, addresses, and contact details.
Put the two incidents together and a pattern emerges. First, a fulfillment partner leaks customer data. Then, a communications-layer vendor gets compromised. Attackers now have physical information and a trusted sending channel. That combination is the ideal setup for a targeted, high-credibility phishing campaign aimed at hardware wallet owners, exactly the people most likely to hold significant crypto assets.
Why This Is More Dangerous Than a Typical Phishing Attack
Most phishing campaigns succeed on volume and hope. This one succeeds on trust. When an email arrives from a domain you recognize, sent by a company you bought hardware from, referencing your real purchase history, every psychological defense drops.
The likely play here is a fake firmware update, a seed phrase verification request, or an urgent security alert asking users to confirm wallet access. Any of these, if clicked and followed, could result in total and irreversible loss of funds. Hardware wallets protect against remote exploits. They do not protect against users being socially engineered into handing over their seed phrase.
What Trezor Holders Should Do Right Now
Trezor will never ask for your 12 or 24-word recovery seed. Full stop. No legitimate communication from any hardware wallet company, under any circumstances, will ever request it.
If you have received any email from Trezor recently, do not click any links. Navigate directly to trezor.io by typing it into your browser. Check official Trezor channels on X for confirmed announcements.
Beyond that, assume your contact information is already in the hands of bad actors. Be suspicious of any outreach, email, SMS, or otherwise, claiming to be from Trezor in the coming weeks.
The broader takeaway for the market: hardware wallet users are being targeted with increasing sophistication. The weakest link is no longer the device. It is the supply chain around it.