Trezor Phishing Attack Exposes Supply-Chain Risks
Trezor confirmed that a compromised third-party email provider enabled attackers to send phishing messages appearing to come from the hardware-wallet maker. The emails falsely warned that 25% of wallets could be affected by an “STM32 entropy vulnerability” and urged users to complete a security check. Trezor said the alert was fraudulent and advised users not to click links or share recovery seeds, wallet backups, PINs, passwords or verification codes. Some messages reportedly passed SPF, DKIM and DMARC checks and used Trezor-linked tracking infrastructure. Trezor closed the affected domain and is investigating the breach. The provider has not been officially named, although researchers linked it to Brevo. The incident followed a ShipMonk breach that may have exposed data from about 81,000 customers, including names, contact details, delivery addresses and order information. There is no evidence that the incidents involved the same attackers or caused crypto losses. Separate research also found that physical access and specialised laser equipment could interfere with firmware checks on Trezor Safe 7, but Trezor said user funds were not at risk. For traders, the Trezor phishing attack highlights ongoing hardware-wallet, supply-chain and social-engineering risks rather than a confirmed protocol vulnerability. The direct price impact is likely limited, but users may temporarily shift funds or reduce trust in affected wallet products.
Neutral
The Trezor phishing attack does not provide evidence of a blockchain, protocol or private-key failure, and no crypto losses have been confirmed. As a result, it is unlikely to create sustained selling pressure across the wider crypto market. In the short term, affected users may move assets, pause purchases or sell wallet-related holdings because of heightened security concerns. Negative sentiment could also weigh on confidence in hardware-wallet providers. However, these reactions are likely to remain contained because the incident involves email infrastructure and social engineering rather than a confirmed vulnerability in the underlying cryptocurrencies. Over the longer term, the breach and the earlier ShipMonk data exposure may increase demand for stronger account security, offline verification and alternative custody arrangements. The separate Safe 7 research adds reputational risk, but Trezor said it does not threaten user funds. Overall, the event is neutral for cryptocurrency prices, with a possible limited and temporary impact on wallet-related sentiment.