Fri. Sep 11th, 2026

Trezor Phishing File Sent Recovery Seeds to Telegram Bot

ByShane Neagle

September 10, 2026 #Trezor
Trezor crypto walletTrezor crypto walletTrezor crypto wallet

A phishing campaign sent through email infrastructure associated with hardware wallet maker Trezor appears to have been designed to transmit victims’ recovery phrases directly to a Telegram bot, adding a more serious technical dimension to a breach initially described as a compromised third-party email provider.

A Trezor forum user who received the phishing email downloaded and inspected an HTML file distributed through the campaign and said the embedded JavaScript was configured to send information entered by victims to Telegram through its bot API.

The finding does not establish that any Trezor recovery phrases were successfully stolen. There is currently no public figure for how many recipients interacted with the malicious file, how many entered sensitive information or whether any cryptocurrency losses have been connected to the campaign.

But the code provides a clearer picture of what attackers intended to do once a recipient followed the phishing flow.

The campaign emerged on Sept. 9 with emails carrying warnings about a supposed “STM32 Entropy Vulnerability.” Recipients were told that a weakness affecting the random-number generation used by Trezor devices could compromise wallet recovery phrases and were directed toward a process intended to determine whether their wallets were affected.

The warning was fake.

Trezor confirmed that its third-party email provider had been breached and said the message did not originate from the company. It instructed users not to click links and said it had taken down the affected domain while investigating how attackers gained access to its legitimate email infrastructure.

The phishing operation was particularly convincing because some messages were delivered through an authenticated Trezor-associated email path rather than simply spoofing the company’s name from an unrelated domain.

Users inspecting the messages reported that they passed standard SPF, DKIM and DMARC authentication checks. Those mechanisms are designed to help receiving mail systems determine whether a sender is authorized to send mail for a particular domain.

Independent technical analysis subsequently linked the campaign to Brevo, the third-party marketing and newsletter infrastructure used to send Trezor emails.

That distinction matters.

In a conventional phishing attack, users can often identify suspicious messages because the sender uses a misspelled domain or because authentication checks fail. In this case, the attackers appear to have gained enough access to trusted outbound infrastructure for the fraudulent messages to pass the same authentication mechanisms used by legitimate communications.

Links inside the emails also reportedly passed through a Trezor-associated mailing subdomain before redirecting users further into the phishing flow.

The malicious HTML analyzed by the forum user was presented as an offline method for checking whether a recovery phrase was vulnerable.

Instead, according to the user’s inspection, JavaScript inside the file was capable of collecting the information entered into the page and transmitting it to a Telegram bot.

A recovery phrase is effectively the master credential for a self-custodial cryptocurrency wallet. Anyone obtaining the phrase can recreate the wallet elsewhere and transfer its assets without requiring possession of the original hardware device.

Trezor repeatedly warns customers never to enter their wallet backup into a website or provide it to another person.

The fake vulnerability story appears to have borrowed heavily from a real security incident involving rival hardware wallet Coldcard.

Coldcard disclosed a serious random-number generation problem this summer that resulted in some wallet seeds being generated with insufficient entropy. The flaw led to substantial bitcoin thefts after attackers reconstructed vulnerable wallet seeds.

Trezor itself published an analysis of the Coldcard incident in late August.

By adapting a genuine and highly publicized hardware-wallet security failure to Trezor devices, the attackers gave their phishing message a technically plausible narrative at a time when hardware-wallet users were already alert to RNG vulnerabilities.

The infrastructure compromise may also extend beyond Trezor.

Similar authenticated phishing emails were reported by users of BitBox and CoinTracking around the same time, with preliminary investigations also pointing toward shared newsletter-provider infrastructure.

The precise nature of the attackers’ access remains unclear.

It is not yet publicly known whether they compromised individual customer accounts at the email provider, obtained administrative access to mailing lists, accessed API credentials or exploited a broader weakness within the provider itself.

There is also no confirmed figure for the number of Trezor email addresses exposed through the incident.

Those unanswered questions now matter as much as the phishing payload itself.

The malicious HTML demonstrates what the attackers wanted from recipients.

The remaining investigation must determine how they gained the ability to deliver it through a trusted sender and whether anyone handed over the keys to their wallets before the campaign was shut down.

Passing Email Authentication Made This Phishing Attack Far More Dangerous

The most important part of this incident is not that criminals built another page asking cryptocurrency users for their recovery phrases.

That happens every day.

What makes this campaign different is that several of the normal defenses users have been taught to rely on appear to have worked exactly as designed — and still produced the wrong answer.

Check the sender domain.

It looked legitimate.

Check whether the email was authenticated.

SPF, DKIM and DMARC passed.

Hover over the link.

At least part of the click path used infrastructure associated with Trezor’s real domain.

For an ordinary user, that is a remarkably convincing set of signals.

The problem is that email authentication proves something narrower than many people assume. It can establish that a message was sent through infrastructure authorized to represent a domain. It cannot establish that the person controlling that infrastructure at that moment was authorized to send that particular message.

If an attacker compromises the authorized sender itself, a perfectly authenticated phishing email is still phishing.

That shifts some of the security burden away from the customer.

Crypto companies often tell users to check domains carefully and ignore suspicious senders. Those remain useful precautions, but they cannot protect against an attacker who gets inside the trusted communications supply chain.

The malicious HTML makes the next stage even more revealing.

An “offline” recovery checker sounds safer than entering a seed phrase on an unfamiliar website. That language may have been deliberately chosen to reassure security-conscious hardware-wallet owners.

But an HTML file running locally can still execute JavaScript and make outbound network requests.

Offline-looking is not the same as offline.

If the reported code was configured to send entered recovery data to a Telegram bot, the attacker had created a very simple collection pipeline: trusted email delivery, a frightening technical warning, a locally opened verification tool and near-instant exfiltration of the wallet’s most valuable secret.

Telegram also gives attackers a convenient receiving mechanism. Bot APIs are easy to automate, work across jurisdictions and allow stolen information to reach an operator without requiring the attacker to maintain obvious custom infrastructure.

The unresolved question is whether the pipeline actually captured anything.

There is an enormous difference between discovering code capable of stealing recovery phrases and demonstrating that victims submitted them.

That evidence could eventually come from victim reports, blockchain movements linked to newly compromised wallets, Telegram infrastructure records or forensic analysis of the phishing backend.

Until then, any claim of actual seed theft should remain cautious.

The same standard should apply to the Brevo compromise.

The evidence strongly supports a compromise involving the trusted email delivery channel, and Trezor itself has confirmed that its third-party provider was breached. But the exact level of access matters enormously.

Stealing one customer’s newsletter credentials is different from compromising Brevo’s underlying platform.

Accessing only an email list is different from controlling authenticated sending infrastructure.

And obtaining campaign permissions is different from stealing broader customer data.

That distinction will determine whether this was a targeted account takeover or a genuine supply-chain security incident affecting multiple crypto companies.

The timing makes the episode especially damaging for Trezor.

The company had already disclosed a separate breach involving shipping provider ShipMonk, which exposed names, email addresses, phone numbers and shipping information belonging to tens of thousands of customers.

There is currently no proof that the ShipMonk data was used in the Sept. 9 email campaign.

But customers do not experience security incidents as neatly separated corporate systems.

They see one company name.

First personal information leaks through one provider. Then highly convincing phishing mail arrives through another provider’s trusted infrastructure.

Even when the Trezor hardware itself remains secure, that sequence weakens the security perimeter around the people using it.

And in self-custody, attackers do not need to break the hardware if they can persuade the owner to hand over the seed.

Financial Markets Analyst and Digital Assets Journalist at  |  More Posts

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.

He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.

Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *