Crypto news report · source clearly identified

Trezor Confirms Email Provider Breach After Fake Security Alert

Hardware wallet maker Trezor says its email service was compromised, leading to a fraudulent alert that falsely warned of a hardware flaw exposing recovery phrases.

Security researcher and hardware wallet manufacturer Trezor has disclosed that a breach of its email provider was used to distribute a counterfeit security alert. The alert claimed a hardware flaw could expose users’ recovery phrases, but Trezor confirmed the claim was false.

What happened

The breach involved unauthorized access to the email service that Trezor uses for communications with its customers. Attackers leveraged this access to send a fabricated warning that suggested a vulnerability in Trezor devices could reveal the secret recovery phrases needed to restore wallets.

Trezor’s response

Trezor issued a statement clarifying that no hardware defect exists and that the alert was a phishing attempt. The company advised users to ignore the message, verify communications through official channels, and remain vigilant against future email‑based scams.

Impact on users

There is no indication that any user data, including private keys or recovery phrases, was actually compromised. The incident underscores the importance of confirming the authenticity of security notices, especially when they involve critical wallet information.

Broader implications

While the breach targeted an email provider rather than Trezor’s core infrastructure, it highlights the ongoing risk of supply‑chain attacks that can affect even well‑established crypto security firms. Users are reminded to follow best practices such as using hardware wallets, keeping recovery phrases offline, and regularly checking official sources for updates.

Source & attribution

News Source

Publisher
Decrypt
Original date
September 9, 2026, 11:02 PM
Original headline
Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider
View original report ↗