--- title: "Trezor supply chain hack moves to postal mail attack" type: "post" post_id: "1701" slug: "trezor-supply-chain-hack-moves-to-postal-mail-attack" canonical: "https://domainsure.com/crypto/trezor-supply-chain-hack-moves-to-postal-mail-attack/" markdown_url: "https://domainsure.com/crypto/trezor-supply-chain-hack-moves-to-postal-mail-attack.md" json_url: "https://domainsure.com/crypto/trezor-supply-chain-hack-moves-to-postal-mail-attack.json" txt_url: "https://domainsure.com/crypto/trezor-supply-chain-hack-moves-to-postal-mail-attack.txt" published: "2026-09-09T15:15:24+00:00" modified: "2026-09-09T15:15:44+00:00" author: "markjr" categories: - "Crypto" tags: site_name: "DomainSure Risk Intelligence Corp." publisher: "" language: "en-US" generator: "easyPress Markdown" generator_version: "1.0.2" --- Background: Crypto hardware wallet-maker Trezor recently [disclosed a customer data breach](https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident) in one of their shipping partners. This is problematic for crypto users in particular, since having one’s home address revealed opens you to so-called “wrench attacks” – which is why we recommend using PO boxes for receiving potentially sensitive items where disclosing your home address could pose security risks. Now that Trezor customers’ addresses are out in the wild, some are reporting postal delivered letters purporting to be from the company, advising them to “migrate their wallets” to a secure upgrade. ![](https://domainsure.com/wp-content/uploads/2026/09/trezor-scam-redacted-scaled.jpeg) A few issues come to light, including that *QR codes can be malicious.* Even if this was a legitimate letter (it empathically isn’t), you should at the very least, use a separate [QR code scanner](https://qrgateway.com/qr-code-scanner) tool that can show you what information is encoded. In this case we can see that it’s not to the official Trezor domain, but to an io-qr.cc subdomain named “trezor” on a QR code redirector service. ![](https://domainsure.com/wp-content/uploads/2026/09/qr-scanner-result.png) We can plug that in to a [Link Expander / Redirect Chain](https://app.domainhelp.com/redirect-chain) and trace all the hops: ![](https://domainsure.com/wp-content/uploads/2026/09/domainhelp-qr-trezor-scam-scaled.png) …and we can see that we’ll ultimately end up on a “qr-trezor” domain that was registered on Sept. 3rd via Nicenic, and using Cloudflare (surprise, and surprise). Of course, this is all to lure the recipient to this page: ![](https://domainsure.com/wp-content/uploads/2026/09/qr-trezor-797x1024.png) Where you will duly be prompted for your seed phrase and your wallet drained. It’s somewhat novel to see a snail mail crossover for an address breach attack vector, but it highlights the risks of malicious QR codes and, as always, lookalike domains. We’ve added the malicious links to the [Domainsure Crypto Defender Threat Feeds](https://domainsure.com/rbl-realtime-blocklists/), and we previously didn’t know about **io-qr.cc**, which has been added to the [Public URL Redirectors feed (PURLs)](https://domainsure.com/domainsure-public-url-redirects-list-purls/) – the latter is not a block list, it’s there for developers to integrate into their link sanitization workflows (there is also an agentic skill for [“Is This a Redirect?”](https://app.domainhelp.com/is-this-a-redirect) over on [DNSskills.md](https://dnsskills.md). The Trezor data breach comes at the worst time, as many users (the author included) were buying them to get out of the blast radius [from July’s Coldcard hack](https://thesovereigncapitalist.io/coinkite-coldcard-security-advisory/).