Hardware crypto wallet maker Trezor has confirmed that one of its email service providers suffered a data breach, potentially exposing hundreds of thousands of its users to targeted scam attempts. The company warned that affected users could receive fraudulent communications designed to look like official Trezor messages. Notably, this marks the second such breach linked to a third-party service that Trezor relies on for its operations.
According to Trezor's disclosure, the breach did not compromise the core hardware wallet system or private keys stored on devices. Instead, scammers gained access to email addresses and are now using them to send phishing emails and fake customer support messages, attempting to trick users into revealing recovery phrases or wallet credentials.
The incident underscores a growing trend where attackers exploit third-party vendors rather than directly attacking hardened crypto infrastructure. Since email-based communication remains a weak link, even security-focused companies like Trezor can find their customers exposed through indirect channels.
As cryptocurrency and digital wallet usage continues to grow in Myanmar, understanding these evolving scam tactics is increasingly important. Users are advised never to click on suspicious links, never share recovery phrases with anyone, and always verify communications through official channels only.
