Trezor Vendor Breach Fuels Phishing Risk
A breach affecting Trezor’s email provider shows how crypto security can be weakened by third-party operational systems rather than the wallet itself.

Crypto security can fail far away from the wallet.
What happened
Trezor confirmed that an attack affecting one of its email providers allowed scammers to send roughly 347,000 phishing emails to customers. The company said its hardware wallets, products and account systems were not compromised.
The exposed risk is customer contact data and trust. Even without access to funds or wallet infrastructure, attackers can use legitimate-looking emails to push users toward fake recovery pages, malicious links or seed-phrase scams.
Why it matters
This is a clean example of third-party vendor risk. Crypto companies often market security around hardware, encryption and self-custody, but customer-facing operations still depend on email platforms, support tooling, analytics vendors and logistics providers.
For attackers, those softer systems can be more attractive than the core product. A phishing email that reaches the right user at the wrong moment can be enough.
The bigger picture
As crypto moves further into mainstream financial infrastructure, operational security will matter as much as technical product security. The weakest link may not be the wallet chip or blockchain protocol, but the vendor sitting quietly inside the customer communications stack.
