Trezor A.I CyberSecurity Scoring
Trezor
Company Information
Website:https://trezor.io
Employees number:195
Number of followers:14,194
NAICS:
Industry Type:Consumer Electronics
Homepage:trezor.io
Trezor Risk Score (AI oriented)
Between 0 and 549
TrezorConsumer Electronics
Updated:
13/08/2026
13/08/2026
527/1000
Critical
C
Trezor Global Score (TPRM)
xxxx
TrezorConsumer Electronics
Score locked

TrezorCritical
Current Score
527C (CRITICAL)
01000
10 incidents
-28.62 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
602
Breach
13 Aug 2026 • Trezor
Trezor and ShipMonk: Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers
Trezor Customers Face Phishing Risks After Third-Party Logistics Breach
527
CRITICAL-75
TRESHI1786631044
Trezor Customers Face Phishing Risks After Third-Party Logistics Breach
On August 10, 2026, hardware wallet manufacturer Trezor disclosed a data breach involving ShipMonk, one of its shipping providers, exposing personal details of thousands of customers. While Trezor’s own systems and devices remained uncompromised, the incident heightened phishing risks for affected users.
The breach impacted 13,689 customers who placed orders between May 10 and August 8, 2026, across the U.S., U.K., Sweden, Colombia, Brazil, Italy, and Portugal. Of these, 11,742 customers had full exposure of names, email addresses, phone numbers, and shipping addresses, while 1,947 had partial exposure limited to names, cities, and emails. Trezor’s 90-day data retention policy limited the scope, as older records were no longer stored by ShipMonk.
ShipMonk, which handles storage and shipping for Trezor, held the exposed data including names, emails, order numbers, phone numbers, and shipping addresses only as required for delivery. Trezor confirmed that no wallet security or firmware was affected, but the leaked details could be weaponized for phishing, spoofed calls, or fraudulent messages impersonating Trezor or financial services.
This marks the first time since Trezor’s 2013 founding that customer phone numbers and shipping addresses have been exposed in a breach. The company has notified affected users via [email protected] and urged caution against unsolicited requests for personal or wallet recovery information.
Trezor is working with ShipMonk to investigate and secure the affected systems. To mitigate future risks, the company plans to introduce an "Anonymous Delivery" option by September 2026 (EU) and end of 2026 (U.S.), featuring neutral packaging, locker pickup, and automatic deletion of shipping identifiers. Operations remain unaffected, and Trezor continues direct customer outreach.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
620
Cyber Attack
29 Jul 2026 • Trezor
Google, Apple, Trezor, Ledger and Discord: macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
Mac Users Targeted in ClickFix Campaign Delivering Atomic Stealer Malware
601
CRITICAL-19
APPDISTREGOOTHE1785342399
Mac Users Targeted in ClickFix Campaign Delivering Atomic Stealer Malware
A new ClickFix social engineering campaign is targeting macOS users, tricking victims into manually installing Atomic macOS Stealer (AMOS) malware by disguising malicious commands as routine verification steps.
The attack begins when users encounter a fake CAPTCHA or error prompt on a compromised or fraudulent website, instructing them to copy a command, open Terminal, and execute it ostensibly to complete a security check. Unlike traditional exploits, this method relies on deception rather than software vulnerabilities, leveraging trust in familiar security prompts to coerce victims into executing the infection themselves.
Once the command runs, it downloads a hidden disk image (DMG) containing Atomic Stealer, which operates stealthily mounting without visible indicators in Finder or on the desktop. The malware may then display a counterfeit macOS authentication dialog, tricking users into entering their password to grant elevated privileges.
Atomic Stealer’s capabilities are extensive, targeting:
- Browser data: Saved credentials, cookies, autofill details, and payment information from Chromium-based browsers (Chrome, Edge, Brave, Opera, etc.) and Firefox.
- System credentials: Apple Keychain passwords, Safari cookies, and Apple Notes.
- Messaging apps: Telegram and Discord desktop data, enabling attackers to impersonate victims or access sensitive communications.
- Cryptocurrency assets: Desktop wallets (Exodus, Electrum, Atomic Wallet, Ledger, Trezor, etc.) and 200+ crypto-related browser extensions, with the ability to replace legitimate wallet apps with malicious versions.
- Files: PDFs, TXT, and RTF documents.
Stolen data is compressed into a ZIP archive and exfiltrated to an attacker-controlled server, where it can be used for account takeovers, financial theft, or follow-on scams.
Kaspersky’s report highlights that ClickFix lures, previously focused on Windows users, are now expanding to macOS, employing tactics similar to a recent Script Editor campaign that also relied on social engineering. The attack’s effectiveness stems from bypassing technical defenses by exploiting user trust victims unknowingly authorize the malware’s installation and grant administrative access.
Legitimate websites never require Terminal commands for verification, and macOS users are advised to treat unexpected password prompts with skepticism. The campaign underscores the growing threat of malware-as-a-service (MaaS) tools like Atomic Stealer, which lower the barrier for cybercriminals targeting Apple’s ecosystem.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
639
Cyber Attack
28 Jul 2026 • Trezor
Exodus and Trezor: Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions
CastleLoader Campaign Expands with Crypto Wallet Spoofing and Browser Session Theft
601
CRITICAL-38
EXOTRE1785241575
CastleLoader Campaign Expands with Crypto Wallet Spoofing and Browser Session Theft
Cybercriminals behind the CastleLoader malware campaign are escalating attacks by deploying sophisticated tools to steal cryptocurrency recovery phrases, login credentials, and active browser sessions. Researchers at Arctic Wolf identified the latest evolution of the campaign, which now targets digital asset holders with fake wallet interfaces and malicious browser extensions.
### How the Attack Works
The operation begins with fake software installers and ClickFix-style prompts, tricking victims into executing harmful PowerShell commands. Once executed, the CastleLoader malware retrieves additional payloads including Python injectors and Rust-based stealers without leaving obvious traces, complicating early detection.
Key components of the campaign include:
- NeedleStealer (Rust-based wallet spoofer): Mimics popular wallet brands (Ledger, Trezor, Exodus) with polished fake interfaces designed to trick users into entering their recovery seed phrases. Unlike traditional exploits, this attack relies on social engineering rather than software vulnerabilities.
- Golang-based malicious browser extensions: Disguised as legitimate tools (e.g., ad blockers), these extensions hijack active browser sessions, allowing attackers to bypass passwords and access accounts without triggering new login challenges.
- Node.js-based injectors: Used in the Noidret campaign, these tools unpack malware in the ProgramData directory alongside legitimate binaries, blending in with normal system activity.
### Why This Matters
- Irreversible wallet theft: Unlike passwords, recovery phrases cannot be reset once stolen, attackers gain permanent control of a victim’s cryptocurrency holdings.
- Session hijacking risks: Stolen browser tokens enable attackers to access accounts without passwords, evading security measures like two-factor authentication.
- Evolving tactics: The campaign reflects a shift from general credential theft to specialized crypto-targeting, leveraging social engineering (fake updates, misleading installers) to deceive users.
### Campaign Clusters & Infrastructure
Arctic Wolf tracked multiple CastleLoader clusters, including:
- Urutyka (PowerShell stagers, NetSupport RAT)
- Garrigin (NSIS installers masquerading as Edge updates)
- Noidret (Node.js-based wallet spoofers)
Indicators of compromise (IoCs) include domains like pub-6728b11f74fd435f926ed25c5f2952bb.r2.dev (Urutyka download server) and IPs such as 91.92.33.167 (Lobshot C2). Malicious files, including walletspoofer.exe and traffic1.exe, were observed in ProgramData and AppData directories.
### Defensive Recommendations (For Security Teams)
- Block listed infrastructure at DNS, firewall, and endpoint layers.
- Monitor unusual activity from PowerShell, Node.js, and Python in user-writable locations.
- Enable PowerShell logging and investigate Mark-of-the-Web (MOTW) removal.
- Restrict unsigned binaries in sensitive directories.
- Review browser extension permissions for unauthorized changes.
The campaign underscores the growing threat of crypto-focused malware, where attackers exploit human trust rather than technical flaws to compromise digital assets.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
652
Cyber Attack
01 Jun 2026 • Trezor
Electrum, Exodus, Ledger and Trezor: Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain
633
CRITICAL-19
ELEEXOLEDTRE1784199019
New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain
Security researchers at SlowMist have uncovered a sophisticated macOS-focused infostealer designed to harvest credentials, wallet databases, and session data for offline cryptocurrency theft. Detected by the MistEye monitoring system, the malware casts a wide net, extracting sensitive information from Apple Keychain, Safari and Chromium browsers, Telegram Desktop, Apple Notes, and multiple wallet applications including Electrum, Exodus, Atomic, Wasabi, Monero, Bitcoin Core, Ledger Live, and Trezor Suite.
The malware’s primary threat lies in its ability to pair stolen wallet databases with potential unlocking material, such as passwords from Keychain or browser stores. While most wallet apps encrypt data locally, attackers can test harvested credentials against exfiltrated wallet files in an isolated environment, bypassing the limitations of online password-guessing attacks. SlowMist demonstrated this by successfully decrypting Atomic Wallet data using a password obtained from the victim’s Keychain. Once a wallet’s recovery phrase or private key is extracted, simply reinstalling the app or changing its password offers no protection.
The malware also employs social engineering tactics, including a fake "Google API Connector" update prompt to capture the victim’s macOS password. It validates credentials using the `dscl` authentication utility, ensuring attackers obtain the correct login details. Additionally, it targets Chrome Safe Storage secrets from Keychain, which can decrypt stored browser logins and cookies.
Telegram users face a separate risk: the stealer copies the `tdata` directory, containing encryption keys and session state. In lab tests, restoring these files on a compatible Mac immediately granted access to the victim’s account without requiring SMS codes or two-factor authentication effectively hijacking an active session. Stolen `tdata` artifacts could also be converted into programmable Telegram API sessions, enabling full chat access.
For Ledger Live and Trezor Suite users, the malware deploys phishing pages disguised as legitimate wallet applications. After removing the real software, it installs lookalike WebView loaders that connect to attacker-controlled sites, tricking victims into entering recovery phrases or PINs under the guise of trusted desktop apps.
The campaign highlights how infostealers exploit the interplay between credentials, encrypted local stores, and user trust. While a stolen wallet database alone may be secure, pairing it with Keychain secrets and reused passwords creates a portable target for offline decryption. Indicators of compromise (IOCs) include malicious domains and IP addresses linked to the phishing infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
669
Cyber Attack
01 May 2026 • Trezor
Google, Ledger Live and Trezor Suite: Reaper macOS Infostealer Abuses Script Editor to Steal Crypto and Passwords
macOS Users Targeted by Reaper Malware Campaign Using Fake App Downloads
649
CRITICAL-20
BLETREGOO1780669490
macOS Users Targeted by Reaper Malware Campaign Using Fake App Downloads
A new malware campaign is targeting macOS users with an updated version of the SHub Stealer, dubbed Reaper, which masquerades as trusted software brands to steal files and cryptocurrency assets. Researchers at SentinelOne first identified the threat, with Moonlock later uncovering additional details on its distribution tactics.
The attack leverages a refined ClickFix technique, bypassing Apple’s recent security updates in macOS Tahoe 26.4, which restricted malicious Terminal commands. Instead of relying on Terminal, the malware uses applescript:// links to automatically open macOS Script Editor, where malicious code is hidden beneath ASCII art and excessive whitespace rendering it invisible unless manually scrolled. When executed, the script triggers a fake Apple security update prompt, tricking users into entering their system password.
The campaign begins on typosquatted domains, such as mlcrosoft.co.com, impersonating legitimate software like WeChat and Miro. Once installed, Reaper checks the victim’s keyboard language shutting down if set to Russian before activating its data-stealing module, modeled after Atomic macOS Stealer (AMOS).
The malware targets documents, PDFs, spreadsheets, and cryptocurrency-related files (e.g., .wallet, .keys), compressing them into 70MB ZIP chunks and exfiltrating them to a command-and-control server at hebsbsbzjsjshduxbs.xyz/gate/chunk. It also steals browser passwords (Chrome, Firefox, Edge) and crypto wallet extensions (1Password, MetaMask), while modifying desktop wallet apps (Ledger Live, Trezor Suite, Exodus) to divert funds. A fake Google Software Update directory is created to maintain persistent backdoor access.
This marks the third campaign in two months using this automated distribution method, signaling an escalating threat to macOS users.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
669
MARCH 2026
666
FEBRUARY 2026
682
Cyber Attack
17 Feb 2026 • Trezor
Trezor: Clickfix Variant ‘Matryoshka’ Deployed To Steal Data From macOS Systems
New 'Matryoshka' Variant of ClickFix Campaign Targets macOS Users with Advanced Evasion Tactics
663
CRITICAL-19
TRE1771316775
New "Matryoshka" Variant of ClickFix Campaign Targets macOS Users with Advanced Evasion Tactics
A recently uncovered evolution of the ClickFix social engineering campaign dubbed Matryoshka is employing sophisticated nested obfuscation techniques to compromise macOS systems. The attack leverages typosquatting, fileless execution, and API-gated communication to evade detection while stealing sensitive data, including passwords and cryptocurrency wallet credentials.
### Infection Chain & Attack Flow
The campaign begins with typosquatting, where attackers register domains mimicking legitimate sites (e.g., comparisions[.]org instead of comparisons.org). Victims redirected to these fake sites encounter a prompt instructing them to copy and paste a malicious Terminal command, bypassing traditional malware delivery methods.
Once executed, the attack unfolds in three stages:
1. Clipboard Injection (Stage 0): The pasted command fetches a rogue shell script (rogue.sh) from an external server, which decodes and decompresses a base64-encoded payload in-memory avoiding disk-based detection.
2. In-Memory Decode & Decompression (Stage 1): The payload is executed without writing to disk, further reducing visibility to security tools.
3. API-Gated Loader (Stage 2): The malware loader communicates with a command-and-control (C2) server (barbermoo[.]xyz) using a custom header (api-key: 5190ef17…) to mask its activity. It suppresses output to evade monitoring.
### Payload Objectives
The final payload deploys an AppleScript designed to:
- Steal passwords via a fake "System Preferences" phishing dialog if automated credential capture fails.
- Target cryptocurrency wallets (e.g., Trezor Suite, Ledger Live) by either replacing the application or tampering with its files to bypass integrity checks.
Stolen data is staged in /tmp/osalogging.zip before exfiltration to the attacker’s server.
### Detection & Artifacts
While Matryoshka’s fileless execution complicates detection, security teams can monitor for:
- Suspicious network activity (e.g., connections to barbermoo[.]xyz or macfilesendstream[.]com).
- Unexpected AppleScript executions (osascript).
- Unauthorized modifications to crypto wallet applications or staging files in /tmp/.
### Key Indicators
- C2 Domain: barbermoo[.]xyz
- Typosquatting Domain: comparisions[.]org
- SHA-256 Hashes:
- 62ca9538889b767b1c3b93e76a32fb4469a2486cb3ccb5fb5fa8beb2dd0c2b90 (sample)
- d675bff1b895b1a231c86ace9d7a39d5704e84c4bc015525b2a9c80c39158338 (rogue.sh)
- 48770b6493f2b9b9e1d9bdbf482ed981e709bd03e53885ff992121af16f76a09 (inner loader)
The Matryoshka variant underscores the growing sophistication of macOS-targeted attacks, combining social engineering with advanced evasion techniques to bypass traditional defenses.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
699
Cyber Attack
01 Jan 2026 • Trezor
Microsoft, Trezor, Audacity, GitHub and Ledger: OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases
New OkoBot Malware Framework Targets Cryptocurrency Users with Advanced Theft Tactics
679
CRITICAL-20
LEDGITMICAUDTRE1784125944
New OkoBot Malware Framework Targets Cryptocurrency Users with Advanced Theft Tactics
A sophisticated malware framework, OkoBot, has emerged as a major threat to cryptocurrency users, employing a multi-stage attack chain to steal recovery phrases, credentials, and wallet data. First observed in January 2026, the campaign builds on the TookPS downloader, which has been active since March 2025.
OkoBot operates as a modular platform with over 202,020 payloads, allowing attackers to deploy capabilities remotely via SSH infrastructure. Initial infections occur through ClickFix social-engineering attacks and trojanized applications hosted on GitHub, including a fake Microsoft SQL Server Management Studio (SSMS) repository that delivered a malicious Audacity installer.
Once executed, TookPS installs an SSH service, establishes a tunnel to attacker-controlled servers, and conducts system reconnaissance identifying security software, harvesting browser data, and preparing for deeper compromise. The malware also enables remote desktop (RDP) access by modifying firewall rules, creating backdoor user accounts, and patching termsrv.dll to allow concurrent sessions.
A key component, HDUtil, bypasses User Account Control (UAC) using Windows RPC and msconfig.exe, while SeedHunter targets Ledger Live, Ledger Wallet, and Trezor Suite by injecting fake recovery prompts. When a victim enters their seed phrase, it is exfiltrated to moonsand[.]store and stored locally in an RC4-encrypted file.
Additional plugins include:
- MC Keylogger – Logs clipboard data, USB devices, and screenshots.
- OkoSpyware – Records keystrokes and video streams from wallet apps and password managers.
Kaspersky researchers detected hundreds of victims across 25+ countries, with the highest concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye. While attribution remains unclear, Russian-language artifacts, Rilide stealer usage, and CIS geoblocking suggest ties to Russian-speaking cybercrime groups.
The malware’s ability to bypass security controls, maintain persistence, and exfiltrate sensitive data makes it a significant risk for cryptocurrency holders and organizations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
699
NOVEMBER 2025
697
OCTOBER 2025
713
Cyber Attack
01 Oct 2025 • Trezor
Ledger and Trezor: New SilabRAT Trojan Hijacks Sessions to Steal Crypto
SilabRAT: A Stealthy Crypto-Draining Malware Emerges as MaaS
694
CRITICAL-19
TRETHE1781108679
SilabRAT: A Stealthy Crypto-Draining Malware Emerges as MaaS
A new remote access trojan (RAT), SilabRAT, has surfaced on dark web forums, designed to bypass passwords and multi-factor authentication (MFA) by hijacking active user sessions to drain cryptocurrency. First advertised in late 2025 by a Russian-speaking threat actor known as o1oo1, the malware is offered as a malware-as-a-service (MaaS) for $5,000 per month. Buyers who often distribute it via email spam and ClickFix lures have reported success rates, with over 90% of infected machines remaining online during month-long campaigns.
SilabRAT evades detection by disguising itself as HijackLoader, a known packer, rather than its true payload. Its standout features include:
- Hidden Virtual Network Computing (HVNC): Operators control infected machines without visible windows or cursor movement, making activity appear as legitimate user sessions.
- Browser-Profile Cloning: The malware copies entire browser profiles including extensions, storage, and device fingerprints to an attacker’s system, allowing stolen sessions to persist even after logouts. A Target.dll module ensures the cloned profile loads seamlessly on the victim’s device.
The malware’s primary goal is cryptocurrency theft. A background module scans for wallets upon infection, attempting to crack passwords using credentials harvested from the victim’s browser. It bypasses Chrome’s App-Bound Encryption via a COM-elevation technique and includes a clipboard clipper to swap wallet addresses mid-transaction. Additional capabilities include:
- Keystroke logging and clipboard monitoring
- Remote desktop access via TightVNC
- A UAC bypass previously used by LockBit and BlackMatter
- Persistence through registry keys or scheduled tasks
Group-IB, which analyzed the threat, warns that SilabRAT’s developer plans to expand its reach by injecting code into Electron-based wallet apps, such as Ledger Live and Trezor Suite. While traditional defenses like MFA and patching can help, the malware’s session-hijacking tactics allow it to bypass even secured logins.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
713
APRIL 2025
727
Cyber Attack
01 Apr 2025 • Trezor
Mozilla, GitHub, Brave Software, Ledger, Trezor and Opera: BoryptGrab Malware Abuses GitHub to Steal Browser and Crypto Wallet Data
New Windows Stealer 'BoryptGrab' Spreads via Fake GitHub Repositories in Large-Scale Campaign
707
CRITICAL-20
THEBRATREMOZGITOPE1773066485
New Windows Stealer "BoryptGrab" Spreads via Fake GitHub Repositories in Large-Scale Campaign
A sophisticated malware campaign is distributing BoryptGrab, a Windows information stealer, through fake GitHub repositories masquerading as free tools, game cheats, and cracked software. The operation, active since at least April 2025, leverages SEO-optimized README files to rank malicious repositories near legitimate projects in search results, tricking users into downloading infected ZIP archives.
### How the Attack Works
Attackers have created over 100 public GitHub repositories advertising enticing but fake software, including:
- "Voicemod Pro download tool"
- "Valorant performance boost"
- "CS2 skin changers"
- Cracked utilities and cheat-style tools
Victims are redirected through GitHub-hosted pages containing Russian-language comments and base64/AES-based URL redirection logic, ultimately landing on a fake GitHub download page that dynamically generates a malicious ZIP file.
### Infection Chain & Malware Capabilities
Once executed, the malware employs multiple infection vectors:
- DLL side-loading (via a malicious `libcurl.dll` that decrypts an embedded launcher using XOR + AES-CBC).
- VBS/PowerShell downloaders that bypass security controls (e.g., adding Microsoft Defender exclusions) and fetch the BoryptGrab stealer from attacker-controlled servers.
- Golang-based downloader (HeaconLoad), which persists via Run-key registry entries and scheduled tasks, beaconing to command-and-control (C2) servers on port 8088.
- TunnesshClient, a PyInstaller-packed backdoor that establishes reverse SSH tunnels, allowing attackers to execute commands, exfiltrate files, or use the victim as a SOCKS5 proxy.
Some variants also deliver obfuscated Vidar stealer payloads via an `/api/custom_exe?build={BUILD_NAME}` endpoint, using XOR encryption and dynamic API resolution to evade detection.
### What BoryptGrab Steals
The C/C++-based stealer includes anti-VM and anti-analysis checks and targets:
- Browser data (Chrome, Edge, Firefox, Opera, Brave, Vivaldi, Yandex, etc.), including stored passwords (bypassing Chrome’s App-Bound Encryption).
- Cryptocurrency wallets (Exodus, Electrum, Ledger Live, Atomic, Binance, Trezor, and dozens more).
- System details, screenshots, Telegram data, and Discord tokens.
- Files with specific extensions (via a "Filegraber" module).
- Installed applications and hardcoded timestamps.
Collected data is compressed and exfiltrated to attacker servers, often followed by the deployment of TunnesshClient for persistent remote access.
### Attribution & Infrastructure
- Russian-language comments and log strings in malware components, along with Russian-hosted IP addresses, suggest a Russian-speaking threat actor, though formal attribution remains unconfirmed.
- C2 servers communicate over ports 5466 and 8088, with build names (e.g., Shrek, Leon, CryptoByte, Sonic, Yaropolk) used to track infection branches.
The campaign demonstrates a mature, evolving ecosystem, combining SEO poisoning, multi-stage downloaders, and SSH-based backdoors to maximize persistence and data theft.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2022
756
Breach
01 Apr 2022 • Trezor
Trezor
Phishing Attack on Trezor Hardware Wallet Users
698
CRITICAL-58
TRE03728522
Trezon, a hardware cryptocurrency wallet, was targeted in a phishing attack through emails as they were sent through one of their opt-in newsletters hosted at MailChimp.
A compromised Trezor hardware wallet mailing list was used to send fake data breach notifications to steal cryptocurrency wallets and the assets stored within them.
Trezor hardware wallet owners began receiving data breach notifications prompting recipients to download a fake Trezor Suite software that would steal their recovery seeds.
However, MailChimp confirmed that their service was compromised by an "insider" targeting cryptocurrency companies.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Trezor ??
What was Trezor's A.I Rankiteo Cyber Score in July 2026 ??
What was Trezor's A.I Rankiteo Cyber Score in June 2026 ??
What was Trezor's A.I Rankiteo Cyber Score in May 2026 ??
What was Trezor's A.I Rankiteo Cyber Score in April 2026 ??
What was Trezor's A.I Rankiteo Cyber Score in March 2026 ??
What was Trezor's A.I Rankiteo Cyber Score in February 2026 ??
What was Trezor's A.I Rankiteo Cyber Score in January 2026 ??
What was Trezor's A.I Rankiteo Cyber Score in December 2025 ??
What was Trezor's A.I Rankiteo Cyber Score in November 2025 ??
What was Trezor's A.I Rankiteo Cyber Score in October 2025 ??
What was Trezor's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Trezor's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Trezor ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Trezor's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?