Skip to content
NetarxImpact Database
Vendor / Supply Chain ImpersonationNo AI reportedConfirmed

Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds

SatoshiLabs (Trezor), via email provider Mailchimp · Cryptocurrency · Czech Republic · April 3, 2022

What happened

Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.

How the deception worked

The deception happened two steps upstream of the victims. Mailchimp employees were socially engineered into giving attackers access to an internal support and account-administration tool, which let the attackers view and export subscriber lists across tenant accounts and specifically target crypto companies. Holding Trezor's real newsletter list, the attackers sent a security-alert email that borrowed Trezor's own incident-response voice, from the plausible domain trezor.us. Recipients who followed the link reached a cloned Trezor Suite with working-looking functionality that asked for the recovery seed, the one secret that grants irreversible control of a hardware wallet.

AI involvement · No AI reported

No AI involvement was reported.

The control that would have caught it· our reading, not a claim from the sources

Hardware wallet vendors should state unconditionally that no update or support flow ever asks for a seed phrase, and email service providers need step-up controls and anomaly detection on internal tools that can export any tenant's subscriber list.

Sources (2)

  1. Ongoing phishing attacks on Trezor users
    Trezor (SatoshiLabs)·blog.trezor.ioOpen ↗
  2. Mailchimp Insider Targets Trezor Crypto Wallets in Phishing Scam
    Decrypt·decrypt.coOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.