Executive Summary
In September 2026, cryptocurrency hardware wallet maker Trezor warned customers that threat actors had breached its third-party email provider and were conducting sophisticated phishing attacks. The attackers sent fake "critical security alert" emails from help@trezor.io, claiming a hardware microcontroller vulnerability in STM32 chips could expose wallet seeds to brute-force attacks. This incident followed a previous breach of Trezor's shipping provider ShipMonk in August 2026, which compromised data from 81,000 customers across multiple countries. The ShipMonk breach exploited a critical SQL injection zero-day vulnerability in the Metabase analytics platform, with the ShinyHunters extortion gang subsequently targeting the company.
This incident highlights the growing trend of supply chain attacks targeting cryptocurrency platforms and the increasing sophistication of phishing campaigns that leverage compromised legitimate infrastructure to bypass security controls and user awareness training.
Why This Matters Now
Cryptocurrency platforms face escalating supply chain attacks as threat actors exploit third-party provider vulnerabilities to conduct sophisticated phishing campaigns, making traditional email security and user training insufficient against attacks leveraging legitimate compromised infrastructure.
Attack Path Analysis
Attackers compromised Trezor's third-party email provider and gained access to customer email lists, then launched sophisticated phishing campaigns impersonating Trezor support using the legitimate domain help@trezor.io. The attack leveraged prior supply chain breaches at ShipMonk to correlate customer data and increase phishing effectiveness. Threat actors established command and control through compromised email infrastructure and potentially exfiltrated additional customer communications. The campaign aimed to steal cryptocurrency wallet seeds and private keys from Trezor users through fraudulent security alert emails.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors breached Trezor's third-party email service provider, gaining unauthorized access to customer email lists and the ability to send emails from the legitimate help@trezor.io domain
Related CVEs
CVE-2023-38646
CVSS 9.8A critical SQL injection vulnerability in Metabase's H2 database connection allows authenticated attackers to execute arbitrary code on the server.
Affected Products:
Metabase Metabase Open Source – < 0.46.6.1
Metabase Metabase Enterprise – < 1.46.6.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Trusted Relationship
Acquire Infrastructure: Domains
Phishing for Information: Spearphishing Link
Exploit Public-Facing Application
Data from Information Repositories: Code Repositories
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Third-Party Service Provider Management
Control ID: 12.8.4
NYDFS 23 NYCRR 500 – Third-Party Service Provider Security Policy
Control ID: 500.11
DORA – ICT Third-Party Risk Management
Control ID: Article 28
CISA ZTMM 2.0 – Data Protection and Classification
Control ID: Data Pillar
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
GDPR – Processor Security Obligations
Control ID: Article 28
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Supply-chain attacks targeting cryptocurrency wallets expose financial institutions to customer data breaches, phishing campaigns, and regulatory compliance violations across multiple frameworks.
Computer Hardware
Hardware wallet manufacturers face direct supply-chain vulnerabilities through third-party providers, enabling sophisticated phishing attacks exploiting microcontroller security concerns and customer trust.
Logistics/Procurement
Shipping and logistics providers become critical attack vectors in supply chains, with vulnerabilities in analytics platforms exposing 81,000+ customer records to extortion gangs.
Information Technology/IT
IT service providers managing email systems and analytics platforms face zero-day SQL injection exploits, creating cascading security incidents across client organizations and regulatory frameworks.
Sources
- Trezor warns users of email provider breach, phishing attackshttps://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/Verified
- Metabase Security Incident Summaryhttps://www.metabase.com/blog/security-incident-summaryVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Trezor Official Twitter Security Alerthttps://x.com/Trezor/status/2097786518110609620Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained lateral movement within the third-party email provider infrastructure and limited the blast radius of this supply chain compromise through network segmentation and controlled access paths.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Comprehensive visibility across cloud infrastructure would likely have enabled earlier detection of unauthorized access patterns and anomalous activity within the third-party email service provider environment.
Control: Zero Trust Segmentation
Mitigation: Network segmentation policies would likely have constrained administrative privilege escalation by limiting lateral access between email service components and restricting the scope of compromised credentials within the infrastructure.
Control: East-West Traffic Security
Mitigation: Traffic inspection and segmentation controls would likely have limited lateral movement between email systems and customer databases, constraining the attacker's ability to correlate data from multiple breach sources.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility across cloud environments would likely have detected persistent access patterns and command channel establishment, potentially identifying the ongoing compromise through traffic analysis and behavioral monitoring.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have constrained large-scale data exfiltration by monitoring and limiting outbound data transfers from email infrastructure to unauthorized external destinations.
While end-user phishing attacks would likely still reach customer inboxes, the constrained infrastructure access and reduced data correlation capabilities would likely have limited campaign sophistication and targeting effectiveness.
Impact at a Glance
Affected Business Functions
- Customer Communication Services
- Order Fulfillment Operations
- Customer Support Systems
- Brand Reputation Management
Estimated downtime: 3 days
Estimated loss: $150,000
Personal information of 81,000 customers including full names, shipping addresses, email addresses, and phone numbers. Additional compromise of email provider enabled sophisticated phishing campaigns using legitimate Trezor domains to target cryptocurrency wallet users.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to isolate third-party email providers and limit lateral movement capabilities between trusted and external communication systems
- • Deploy egress security controls with FQDN filtering to detect and prevent unauthorized outbound communications from compromised email infrastructure
- • Establish multicloud visibility and anomaly detection to identify suspicious email sending patterns and unauthorized domain usage across supply chain partners
- • Implement encrypted traffic inspection capabilities to monitor communications between internal systems and third-party email providers for signs of compromise
- • Deploy threat detection systems with baselining capabilities to identify abnormal email sending volumes and patterns that indicate supply chain compromise



