Trezor, the maker of one of the most widely used hardware wallets for cryptocurrency, has issued a warning to its customer base after learning that threat actors who compromised the company's third-party email provider are now using the stolen data to launch phishing attacks against users.

Trezor issued the warning on 11 September, telling customers that the breach of its email service vendor had been exploited to target them with deceptive messages. The provider's identity and the full scope of exposed data have not been disclosed, according to BleepingComputer's reporting.

A breach one layer removed

The incident highlights a persistent tension in the self-custody model that hardware wallets are built to serve. The entire value proposition of a device like a Trezor is that private keys never leave the hardware, meaning that even a full compromise of a user's laptop or smartphone does not, in theory, expose the cryptographic material needed to move funds.

Yet the human-facing layer — email, support portals, account notifications — remains a soft target. A phishing email that convinces a user to reveal credentials or take other actions that could lead to asset loss bypasses the hardware protection entirely. The wallet is secure; the person holding it is not.

This is not a new observation, but the Trezor warning gives it a concrete, current example. The attack vector is not the wallet firmware, not the USB interface, not the blockchain itself. It is an email inbox, accessed on a phone or a laptop, where a convincing message can override years of security discipline.

Why the stakes are higher here

For users of traditional financial services, a phishing incident that leads to a fraudulent transfer may be recoverable through chargeback mechanisms, fraud insurance, or regulatory recourse. Self-custody cryptocurrency holders have no such backstop. Once a transaction is confirmed on-chain, it is irreversible. There is no customer service line to call, no bank to file a dispute with. The loss is total and permanent.

This asymmetry means that a phishing campaign targeting hardware wallet users carries a different weight than one targeting, say, online banking customers. The same social-engineering technique that might cost a bank customer a few hundred dollars in a recoverable fraudulent transfer can cost a self-custody holder their entire portfolio with no path to recovery.

What users should do

While the specifics of the campaign remain limited in the available reporting, the general defensive posture is straightforward. Any unsolicited email requesting seed phrases, PINs, or transaction approvals should be treated as fraudulent — legitimate wallet vendors will never ask for this information. Users should verify the sender's address and the domain of any links before clicking, since phishing emails originating from a breached provider may carry legitimate-looking headers. Auditing third-party services that have access to an email account and revoking permissions that are no longer needed is a sensible precaution. And if a user has already interacted with a suspicious message, the safest course is to move any assets to a fresh wallet generated on a clean device and treat the compromised wallet as burned.

A reminder about the supply chain

The Trezor warning is a reminder that vendor security extends well beyond the product itself. The email provider, the cloud hosting the support portal, the SaaS tools behind customer communication — each is a potential entry point for an attacker who ultimately wants to reach the end user. For the open-source and self-custody communities, which tend to place heavy trust in the technical integrity of the tools they use, the human and third-party layers deserve equal scrutiny.

The full details of the breach, including the identity of the compromised provider and the precise data exposed, may emerge in the coming days. Until then, the safest assumption for any Trezor user is that the phishing emails are already in the wild.


Trezor 是其中一款應用最廣泛的加密貨幣硬件錢包製造商,近日向用戶發出警告,指有威脅行為者入侵了其第三方電郵供應商,並正利用竊取的資料對用戶發動釣魚攻擊。

Trezor 於 9 月 11 日發出警告,告知客戶其電郵服務供應商遭入侵後,已被利用來向用戶發送欺騙性訊息。據 BleepingComputer 報道,該供應商的具體身份及洩露資料的完整範圍尚未公開。

一層之隔的漏洞

此事件凸顯了硬件錢包所服務的自管模式中存在的一項持續張力。Trezor 這類設備的全部價值主張在於私鑰絕不離開硬件,這意味著即使用戶的筆記型電腦或智能手機被完全入侵,理論上也不會暴露轉移資金所需的加密材料。

然而,面向用戶的層面——電郵、支援平台、帳戶通知——仍然是薄弱環節。一封說服用戶透露憑證或採取其他可能導致資產損失行動的釣魚電郵,完全可以繞過硬件保護。錢包本身是安全的,但持有錢包的人未必是。

這並非新發現,但 Trezor 的警告為之提供了一個具體而時效性強的案例。攻擊向量不是錢包韌體,不是 USB 接口,也不是區塊鏈本身。而是用戶在手機或筆記型電腦上瀏覽的電郵收件箱,一封說服力十足的訊息足以瓦解多年培養的安全紀律。

為何此處風險更高

對於傳統金融服務用戶而言,因釣魚事件導致的欺詐轉帳或可透過拒付機制、欺詐保險或監管途徑追回。自管加密貨幣持有者則沒有這樣的後盾。一旦交易在鏈上確認,便不可逆轉。沒有客服熱線可撥打,沒有銀行可提出爭議。損失是徹底且永久的。

這種不對稱性意味著,針對硬件錢包用戶的釣魚行動,其嚴重程度遠超針對網上銀行客戶的類似行動。同一種社會工程手法,可能只令銀行客戶損失數百美元且可追回的欺詐轉帳,卻可令自管持有者損失整個投資組合,且毫無追回途徑。

用戶應如何應對

雖然現有報道中關於此釣魚行動的具體細節有限,但一般的防禦姿態十分明確。任何未經請求、要求提供助記詞、PIN 或交易授權的電郵,均應視為欺詐——正當的錢包供應商絕不會索取此類資訊。用戶在點擊任何連結前,應核實發件人地址及連結域名,因為源自被入侵供應商的釣魚電郵可能攜帶看似合法的郵件標頭。審計擁有電郵帳戶存取權限的第三方服務,並撤銷不再需要的權限,是一項合理的預防措施。若用戶已與可疑訊息互動,最安全的做法是將資產轉移至在乾淨設備上新生成的錢包,並將已受影響的錢包視為報廢。

供應鏈安全的提醒

Trezor 的警告提醒我們,供應商安全遠不止於產品本身。電郵供應商、託管支援平台的雲端服務、客戶溝通背後的 SaaS 工具——每一項都是攻擊者最終企圖觸達終端用戶的潛在入口。對於開源及自管社群而言,由於往往高度依賴所用工具的技術完整性,人因層面及第三方層面同樣值得同等審視。

此次入侵的完整細節,包括被入侵供應商的具體身份及精確洩露的資料,或將在未來數日逐步披露。在此之前,任何 Trezor 用戶最穩妥的假設是:釣魚電郵已經在流通之中。

新聞來源 / Original News Source