Crypto news report · source clearly identified
Trezor Confirms Email Provider Breach After Fake Security Alert
Hardware wallet maker Trezor says its email service was compromised, leading to a fraudulent alert that falsely warned of a hardware flaw exposing recovery phrases.

Security researcher and hardware wallet manufacturer Trezor has disclosed that a breach of its email provider was used to distribute a counterfeit security alert. The alert claimed a hardware flaw could expose users’ recovery phrases, but Trezor confirmed the claim was false.
What happened
The breach involved unauthorized access to the email service that Trezor uses for communications with its customers. Attackers leveraged this access to send a fabricated warning that suggested a vulnerability in Trezor devices could reveal the secret recovery phrases needed to restore wallets.
Trezor’s response
Trezor issued a statement clarifying that no hardware defect exists and that the alert was a phishing attempt. The company advised users to ignore the message, verify communications through official channels, and remain vigilant against future email‑based scams.
Impact on users
There is no indication that any user data, including private keys or recovery phrases, was actually compromised. The incident underscores the importance of confirming the authenticity of security notices, especially when they involve critical wallet information.
Broader implications
While the breach targeted an email provider rather than Trezor’s core infrastructure, it highlights the ongoing risk of supply‑chain attacks that can affect even well‑established crypto security firms. Users are reminded to follow best practices such as using hardware wallets, keeping recovery phrases offline, and regularly checking official sources for updates.
Source & attribution
News Source
- Publisher
- Decrypt
- Original date
- September 9, 2026, 11:02 PM
- Original headline
- Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider