Trezor's email provider has been breached

(twitter.com)

19 points | by andreyazimov 2 days ago ago

7 comments

  • io84 2 days ago ago

    Their devices have never been [known to be] remotely breached, but still…

    2022: Their Mailchimp account breached

    2024: Their support ticket portal breached

    2025: Support contact form sent phishing via official auto-replies

    Aug 2026: Shipping partner ShipMonk breached

    Sep 2026: Email provider breached

    Anything Trezor knows about you should be considered thoroughly compromised.

    • wmf 2 days ago ago

      B2B SaaS doesn't have the level of security that crypto needs.

  • dddw a day ago ago

    I read that as "Trent Reznor's email was hacked" which would have less impact, but contains more interesting info I bet.

    • DiabloD3 a day ago ago

      Trent Reznor on good email providers: "I just want something I can never have" (maybe)

  • joecool1029 a day ago ago

    I’ve complained upstream to them before about their (lack of) security processes making downstream distro package management more difficult: https://github.com/trezor/trezord-go/issues/293

  • DavCreator a day ago ago
  • toomuchtodo 2 days ago ago

    https://archive.today/H4hbC

    "Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.

    We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain."