On September 9, hackers compromised a third-party mailing service used by Trezor, misleading users with a fake warning regarding vulnerabilities in hardware wallets.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating…
— Trezor (@Trezor) September 9, 2026
Users reported receiving emails from Trezor Security with the subject line "Critical Security Alert: STM32 Entropy Vulnerability," which claimed there was a serious issue with the random number generation in STM32 microcontrollers.
One recipient, Marcello Paz, noted that the email successfully passed Gmail's authenticity checks.
Hello @trezor,
I received a “Critical Security Alert: STM32 Entropy Vulnerability” email today (9 Sep 2026).
Gmail shows From: Trezor Security <help@trezor.io>, Return-Path noreply@mailing.trezor.io, Sendinblue campaign, DKIM/SPF/DMARC pass for https://t.co/69NqnLtwGr.
Body… pic.twitter.com/jKsngEyKXS
— Marcello Paz (@MHPaz) September 9, 2026
The phishing email claimed that approximately one in four devices might have a factory defect in the random number generator, potentially compromising the security of recovery seed phrases used by wallets.
Users were urged to click on a link to check if their model was affected.
Trezor confirmed that they have disabled the domain involved in the attack and are currently investigating how the hackers gained access to the mailing service's infrastructure. However, Trezor did not disclose the name of the provider or the number of recipients affected by the phishing attempt.
BitBox Users Also Affected
Customers of BitBox faced a similar phishing attack. The project team confirmed the incident.
@BitBoxSwiss Könnt ihr bitte bestätigen, ob diese E-Mail tatsächlich von euch stammt bzw. ob die darin beschriebene Sicherheitslücke real ist? Ich gehe davon aus, dass es sich um Brevo-Mail-Tracking-/Weiterleitungslink handelt.
Besonders irritierend finde ich den enthaltenen… pic.twitter.com/IwWWUjg6P9
— Matthias Friedrich (@matt_free_da) September 9, 2026
«Под такие же атаки попали и еще несколько биткоин-компаний; по всей видимости, все мы пользуемся услугами одного и того же провайдера рассылок. Мы разослали всем подписчикам нашей рассылки предупреждение о фишинге, связались с провайдером и сообщили о поддельных доменах. Большинство фейковых ссылок, судя по всему, уже удалено», — отметили разработчики.
It should be noted that in August, Trezor disclosed a breach involving another contractor, logistics firm ShipMonk, which affected over 80,000 customers.
