Trezor, a leading hardware wallet provider, warned users on September 10 that a third‑party email service had been compromised, enabling attackers to send spoofed messages that mimicked the company’s communications.
The fraudulent emails, bearing the subject “Critical Security Alert: STM32 Entropy Vulnerability,” claimed that a serious hardware‑level flaw existed in the STM32 microcontrollers used in Trezor devices and urged recipients to click malicious links.
- Trezor said attackers used a breached third‑party email provider to send spoofed phishing messages.
- Fake emails falsely claimed a critical STM32 vulnerability affected hardware wallets.
- BitBox reported similar phishing attempts, while a Casa executive suggested a shared email provider may have been compromised.
Trezor confirmed the messages were illegitimate, advised users not to click any links, and announced it was sending an update to affected customers.
Fraudulent Emails Mimic a Legitimate Vulnerability Warning
Trezor said it had shut down the exploited domain and was investigating how the attackers gained access to the infrastructure used in the campaign.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating…
— Trezor (@Trezor) September 9, 2026
Security firm PeckShield reported that the phishing sender was spoofed to appear as help@trezor.io.
The malicious correspondence alleged a “critical hardware‑level vulnerability” in STM32 chips, falsely stating that a quarter of Trezor wallets were impacted due to insufficient entropy in private‑key generation— a flaw that, if genuine, could expose seed phrases and jeopardize users’ assets.
Trezor also noted that the phishing email asked recipients to share their wallet backup information.
BitBox Also Warns of Phishing
On the same day, Swiss hardware wallet maker BitBox alerted its users to phishing attempts that impersonated the brand.
BitBox reported that deceptive emails claiming to be from the company were circulating.
There is currently a phishing email going around that’s pretending to come from us.
Please do not follow the instructions in the email!
We are currently investigating. https://t.co/vKK4VxYPm3
— BitBox (@BitBoxSwiss) September 9, 2026
Nick Neumann, co‑founder and CEO of Bitcoin self‑custody firm Casa, suggested on X that a shared marketing email provider might have been compromised, potentially affecting Trezor, BitBox and other companies.
There are convincing phishing emails going out right now from hardware wallet companies (have heard Trezor and Bitbox at least). It’s likely that a marketing email provider was compromised. That will mean more customer emails are leaked.
Stay frosty and don’t trust provider… pic.twitter.com/jHtdRE9S2A
— Nick Neuman (@Nneuman) September 9, 2026
ShipMonk Data Breach
The phishing incident follows a separate supply‑chain breach disclosed by Trezor the previous month.
In August 2026, Trezor’s shipping contractor ShipMonk exposed personal data of 80,689 customers. The leaked information primarily comprised names, phone numbers and addresses, while 1,947 customers had only their names, cities and email addresses disclosed.
Why This Matters
Phishing campaigns that masquerade as trusted hardware wallet brands can trick users into revealing recovery phrases or backup data, putting their cryptocurrency holdings at risk. The episodes also underscore the security challenges posed by third‑party vendors that handle customer communications and data.
Also Read
- Paolo Ardoino says 650 million people decentralized US debt, but Tether still controls the T-bills
- Osmosis Freezes 22.65 BTC Following Nomic Forwarding Vulnerability and Asset Imbalance
- Hoskinson Mocks LAPTOP Crash as Hunter Biden Denies Rug Pull Allegations
- Forex Today: ECB rate decision, US producer inflation data to lift volatility

