Subscribe to our Telegram channel!

Trezor warned users about a phishing attack following a breach at its service provider

September 10, 2026 · 7:39 am 2 min read

Trezor, a manufacturer of hardware crypto wallets, reported that hackers compromised a third-party email provider used by the company and exploited it to send phishing emails. The emails were disguised as official security alerts from Trezor itself.

The fake message, with the subject line «Critical Security Alert: STM32 Entropy Vulnerability,» claimed that the company’s engineers had discovered a critical vulnerability in the STM32 microcontrollers used in the devices. According to the email, the flaw allegedly affects one in four devices and could compromise the randomness of recovery phrase generation—that is, making them more predictable to attackers.

«Please be aware: the email with the subject line ‘Critical Security Alert: STM32 Entropy Vulnerability' is not from us—it is a phishing attempt. Do not click on any links,» Trezor wrote on its X account.

The company blocked the domain used in the attack and launched an investigation into how the attackers managed to gain access to infrastructure associated with Trezor’s legitimate domain. The official warning was issued only after 4:30 p.m. Eastern Time—several hours after a number of users reported receiving suspicious emails from an address similar to the genuine one.

Casa co-founder and CEO Nick Neumann suggested that the attack extends beyond a single brand. According to him, BitBox users also received similar emails. «It appears that a marketing email provider was compromised. Be on your guard and do not trust emails from providers that urge you to click on suspicious links,» he wrote.

Bitcoin security researcher and Casa’s Chief Security Officer Jameson Lopp also highlighted the potential scale of the incident. «Attackers may have compromised the email providers used by Trezor and BitBox. Malicious emails are being sent out about allegedly vulnerable random number generators that require security updates—and these emails do not appear to be fake. No actual security alert has been issued,» he wrote.

This is not the first data breach involving Trezor in recent times. Previously, the company reported a breach at logistics provider ShipMonk, which exposed the personal data of 80,689 customers—including names, email addresses, phone numbers, and mailing addresses—to the public. At the time, Trezor also warned that leaks of this kind could be exploited for more sophisticated phishing campaigns.

BTC

$78,196.73

-1.62%

ETH

$2,476.38

-1.27%

BNB

$718.70

-4.98%

XRP

$1.38

-3.16%

SOL

$101.28

-2.87%

All courses
Loading next article…
Show more