Live coverage, refreshed hourly — new drama arrives while you sleep.

Pixel art rendition of this story
crypto breach

Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

TechCrunch·

Hardware cryptocurrency wallet manufacturer Trezor has confirmed a significant data breach stemming from one of its third-party email providers. This security incident has directly exposed the email addresses of potentially hundreds of thousands of crypto owners, creating a direct pipeline for malicious actors. Following the breach, scammers have wasted no time, actively targeting these exposed individuals with phishing attempts designed to steal their valuable digital assets.

The compromised data, primarily email addresses, gives cybercriminals a crucial entry point for social engineering. While the specific details of the email provider remain undisclosed, the sheer scale of affected users indicates a widespread vulnerability in Trezor's external service chain. Such a breach can enable sophisticated phishing campaigns, where scammers impersonate legitimate entities to trick users into divulging critical information like wallet recovery phrases or private keys, leading to irreversible loss of funds.

Adding a worrying layer to this incident, reports indicate that this is not an isolated event. This marks the second time a data breach has impacted a company within Trezor's operational ecosystem, specifically involving a third-party vendor. This pattern raises serious questions about the diligence of Trezor's vendor selection process and the overall resilience of its supply chain security, leaving its user base seemingly vulnerable to recurring external compromises.

Our take

Live commentary on a developing story, not a final verdict.

Oh, Trezor. You'd think a company whose entire existence hinges on securing highly valuable digital assets would have its third-party security locked down tighter than a drum. But no, here we are again, with hundreds of thousands of crypto owners’ emails floating around in the ether, courtesy of another one of your "trusted" providers getting absolutely shelled. It's giving "fool me once, shame on you; fool me twice, maybe re-evaluate your entire vendor selection process." This isn't just an inconvenience; it's a direct pipeline for opportunistic scammers to prey on your user base, and frankly, it looks like a severe case of negligence by proxy.

The sheer audacity of these repeat offenses truly makes you wonder. If your core business is hardware security, shouldn't safeguarding the path to that hardware be just as paramount? An email breach might seem minor, but in the crypto world, it's a goldmine for phishing attempts that can empty wallets faster than you can say "not your keys, not your coins." It highlights a broader vulnerability across the crypto industry: many companies focus heavily on their own product's security but often overlook the glaring holes in their external services. The drama is less about hackers' ingenuity and more about corporate blind spots.

This is our take on a developing story, not the final word — read the original reporting at TechCrunch ↗

← Back to archive