TLDR
- Trezor’s third-party email provider was breached, allowing hackers to send phishing emails from its official domain
- The fake email warned of an “STM32 Entropy Vulnerability” and urged users to update their devices
- BitBox users received similar phishing emails, suggesting the attack may extend across hardware wallet email providers
- Trezor took down the compromised domain and launched an investigation
- This follows a ShipMonk data breach last month that exposed personal data of over 80,000 Trezor customers
Trezor confirmed on Wednesday that its third-party email provider was breached. Hackers used the access to send phishing emails from what looked like a legitimate Trezor address.
⚠️ALERT: Trezor warns hackers have breached its email provider and are sending phishing emails from its legitimate domain.
The fake email claims a "Critical Security Alert: STM32 Entropy Vulnerability" that could expose your recovery phrase.
Trezor confirms it is NOT real and… pic.twitter.com/RW3y0C4E7h
— Coin Bureau (@coinbureau) September 10, 2026
The fake email was titled “Critical Security Alert: STM32 Entropy Vulnerability.” It claimed that a hardware flaw in Trezor devices could weaken the randomness of users’ recovery phrases, potentially putting funds at risk.
Trezor was quick to respond on X. “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” the company wrote.
The company said it took down the domain used in the attack and is now investigating how the hackers gained access.
The email appeared to be timed to exploit fears around the recent Coldcard vulnerability, which cost users more than $130 million in Bitcoin.
BitBox Also Targeted
Swiss hardware wallet maker BitBox reported similar phishing emails were sent to its users on the same day. This raised concerns that the attack may not be limited to Trezor alone.
Really brutal. The phishing email is written quite convincingly, and it comes from the official Trezor domain.
At least tens of millions will be lost; hopefully not hundreds of millions. Insane f*ckup from Trezor. https://t.co/GBVcqBEJVh pic.twitter.com/4xw8QM8bvi
— FatMan (@FatManTerra) September 9, 2026
Casa CEO Nick Neuman said on X that a shared email marketing provider was likely compromised. “Stay frosty and don’t trust provider emails that try to get you to take actions via sketchy looking links,” he said.
Jameson Lopp, Casa’s Chief Security Officer, echoed those concerns. He warned that threat actors may have breached email providers used by both Trezor and BitBox, and that the emails were not spoofed but sent from real addresses.
Crypto commentator MHPaz shared screenshots of the email, confirming it carried official domain names and signatures that looked authentic.
A Pattern of Breaches
This is not the first security issue Trezor has faced recently. Last month, a breach at shipping provider ShipMonk exposed data belonging to 80,689 customers, including names, emails, phone numbers, and shipping addresses.
Trezor warned at the time that the leaked data could be used in more targeted phishing attacks. That warning now appears to have been well-founded.
In June, Ledger’s security team also disclosed a lab-based hardware vulnerability in the TROPIC01 chip used in the Trezor Safe 7. Trezor said no user funds were at risk from that finding.
Hardware wallet users are being advised not to click links in any security-related emails from wallet providers until further notice. Always verify alerts directly on the official website.
No funds have been confirmed lost as a result of the current phishing campaign.







