Summary
- Trezor disclosed a breach of its third-party email provider, which was exploited to send phishing emails.
- The fraudulent email falsely warned of a hardware vulnerability affecting recovery phrases on certain Trezor devices.
- Security experts have indicated that similar phishing attempts against BitBox users may suggest a wider issue affecting hardware wallet email services.
Trezor, the hardware wallet manufacturer, issued a warning to its users on Wednesday regarding a breach of its third-party email provider, which was used to disseminate phishing emails masquerading as urgent security notifications.
“Please note that the email titled ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not legitimate and is a phishing attempt. Avoid clicking any links,” Trezor posted on X.
Myriad: How high will Bitcoin go in September? Click to make your prediction.The company has since disabled the domain implicated in the attack and is investigating how hackers accessed its legitimate domain.
The phishing email falsely claimed that Trezor engineers had identified a “critical hardware-level vulnerability” in the STM32 microcontrollers utilized in their devices. It alarmingly suggested that this flaw impacted around 25% of devices and could compromise the randomness of recovery phrases, likely playing on recent concerns stemming from the Coldcard exploit that resulted in over $130 million in Bitcoin losses for users.
Trezor released a statement labeling the email as fraudulent shortly after 4:30 p.m. Eastern Time, although several users had already reported receiving the phishing email from what seemed to be an authentic Trezor email address.
Nick Neuman, co-founder and CEO of Casa, suggested that this phishing campaign might extend beyond Trezor, noting that he had received similar reports from BitBox users.
“It’s probable that a marketing email service was compromised,” Neuman stated on X. “Stay vigilant and be cautious with provider emails that prompt you to click on dubious links.”
Hello @trezor,
I received a “Critical Security Alert: STM32 Entropy Vulnerability” email today (9 Sep 2026).
Gmail shows From: Trezor Security <help@trezor.io>, Return-Path noreply@mailing.trezor.io, Sendinblue campaign, DKIM/SPF/DMARC pass for https://t.co/69NqnLtwGr.
Body… pic.twitter.com/jKsngEyKXS
— Marcello Paz (@MHPaz) September 9, 2026
Jameson Lopp, a Bitcoin security researcher and Casa’s Chief Security Officer, echoed similar concerns.
“Threat actors may have compromised the email provider(s) used by Trezor and BitBox,” he noted. “Malicious emails suggesting both have poor random number generators requiring security updates are being sent, and these emails do not appear to be spoofed,” Lopp commented on X. “No such security advisory has been issued!”
In August, Trezor and fellow hardware wallet producer Foundation alerted users to phishing attacks exploiting fears over hardware wallet security after vulnerabilities in Coldcard devices were revealed.
That same month, Trezor reported that a data breach at shipping provider ShipMonk had exposed personal information of 80,689 customers, including names, email addresses, phone numbers, and shipping details, warning that this leaked data could facilitate more advanced phishing attacks.
