
Trezor has warned customers about a phishing campaign after a third-party email provider used by the hardware-wallet company was breached, allowing attackers to send a fake security alert that appeared to come from Trezor. The email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” falsely claimed that a vulnerability in STM32 chips could put users’ recovery phrases at risk.
Trezor posted on X and stated that the message was fraudulent, urged recipients not to click its links and said it had taken down the associated domain. The company is investigating how attackers gained access to its legitimate email infrastructure.
The incident comes shortly after a separate breach at Trezor’s logistics provider exposed data belonging to more than 80,000 customers, adding to concerns about how third-party services can create security risks for cryptocurrency companies and their users.
Trezor Confirms Email Provider Breach Behind Phishing Campaign
Trezor confirmed that its third-party email provider had been breached and warned users about the fake STM32 security alert. The company said it had taken down the domain used in the campaign and was investigating how attackers gained access to its legitimate domain.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating…
— Trezor (@Trezor) SEPTEMBER 9, 2026
The phishing email was designed to resemble a genuine security advisory. Users reported receiving messages that appeared to come from legitimate Trezor addresses, including help@trezor.io.
Reports on the Trezor forum also said the sender appeared legitimate, while the linked website requested sensitive wallet information. Other forum users reported that the phishing emails appeared to have been sent through Trezor’s mailing infrastructure, although the technical details remain under investigation. The distinction between the email infrastructure and Trezor’s wallet technology is important. Trezor has not said that its hardware wallets or recovery seeds were compromised.
The immediate risk is instead phishing. Trezor’s security guidance says legitimate communications will never ask users to provide their wallet backup or recovery seed, which can give an attacker control over cryptocurrency if disclosed. The campaign has drawn concern because the message looked convincing.
Crypto commentator FatMan said the phishing email appeared to come from Trezor’s official domain and warned about potential financial losses.
BitBox Reports Similar Phishing Activity As Earlier Trezor Breach Adds Context
Hardware-wallet company BitBox said its preliminary review found that its newsletter provider was likely compromised after phishing emails were sent to subscribers. The company said multiple Bitcoin companies appeared to have been targeted and that they seemed to share the same newsletter provider.
Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised.
Multiple other Bitcoin companies got targeted as well, and it appears that we all share the…
— BitBox (@BitBoxSwiss) SEPTEMBER 9, 2026
BitBox said it warned subscribers, contacted the provider and reported the phishing domains. The company said most of the phishing links had already been taken down, while its investigation was continuing. The statement does not establish that the Trezor and BitBox incidents were carried out by the same attackers, but the apparent involvement of a shared newsletter provider is relevant.
The Trezor phishing campaign also follows the company’s separate breach at ShipMonk, its logistics provider. Trezor initially disclosed that 13,689 customers were affected. An update later added approximately 67,000 U.S. customers whose older records had remained in ShipMonk’s systems, bringing the reported total to 80,689 customers.
The exposed information included names, email addresses, phone numbers, shipping addresses and order numbers. Trezor said the information could increase the risk of phishing, fraudulent calls and physical-security threats. The company has not said that the ShipMonk incident compromised its wallet products or customer funds.
The earlier breach does not establish a direct connection to the current email-provider incident. It does, however, show how third-party services can become part of the security risk around cryptocurrency products.
The current phishing campaign relies on a trusted communication channel, while the earlier incident exposed information that could make later attempts at impersonation more convincing. Moreover, the latest incident is Trezor’s “third vendor breach” in four weeks, referring to the email-provider incident and earlier exposures.
