
Trezor hardware wallet users are facing a new wave of targeted phishing attacks. According to reports in professional communities, attackers are distributing emails disguised as official notifications from the manufacturer, containing fake warnings about an alleged critical vulnerability discovered in the devices' software.
An X user under the alias x3ideRaven reported receiving such a phishing email. According to him, he purchased a hardware wallet the day after the period the company identified as when the data breach occurred, yet despite this, he began receiving fraudulent messages. This fact indicates that attackers are using databases obtained from various sources, not limited to a single incident.
In the content of the fake email, the attackers claimed the existence of a "critical entropy vulnerability in the firmware" of Trezor devices. According to the fraudulent scheme, a bug in the 2021 software update allegedly could have affected the seed phrase generation process on certain devices. The email contained a technical claim that due to a configuration error, vulnerable firmware versions could have used a non-cryptographic pseudorandom number generator instead of a hardware true random number generator. The attackers claimed this could have reduced the entropy of the seed phrase from 128 to 40 bits, theoretically lowering the cryptographic strength of the generated keys.
Trezor representatives officially confirmed the existence of the new wave of phishing attacks. "We have confirmed that attackers are using a combination of data from different database leaks across several cryptocurrency services. It is quite possible that some KYC data may have been compromised, and the attackers are now trying their luck," the company's official statement noted.
The Trezor team referenced a previous security incident involving the compromise of a third-party tool and the email addresses of newsletter subscribers. Company representatives suggested that the current phishing campaign may be directly linked to that incident, as the attackers gained access to users' contact information. Trezor also added that they have already implemented technical and organizational measures to prevent future data leaks.
The context of the current phishing campaign includes a recent data security incident. Approximately two weeks before reports of the new phishing wave emerged, Trezor disclosed a leak of customer personal data that occurred as a result of a breach of the infrastructure of its logistics partner ShipMonk. The incident affected 13,689 customers whose data may have fallen into the hands of attackers and subsequently been used to personalize phishing attacks.
Information security specialists recommend that hardware wallet users critically evaluate any emails containing references to critical vulnerabilities or demands for immediate action. Official security notifications are always published on the manufacturer's verified resources and never require entering seed phrases or following suspicious links to "update" or "fix" devices.
