Thursday, September 10, 2026

Trezor, a leading hardware wallet provider, warned users on September 10 that a third‑party email service had been compromised, enabling attackers to send spoofed messages that mimicked the company’s communications.

The fraudulent emails, bearing the subject “Critical Security Alert: STM32 Entropy Vulnerability,” claimed that a serious hardware‑level flaw existed in the STM32 microcontrollers used in Trezor devices and urged recipients to click malicious links.

  • Trezor said attackers used a breached third‑party email provider to send spoofed phishing messages.
  • Fake emails falsely claimed a critical STM32 vulnerability affected hardware wallets.
  • BitBox reported similar phishing attempts, while a Casa executive suggested a shared email provider may have been compromised.

Trezor confirmed the messages were illegitimate, advised users not to click any links, and announced it was sending an update to affected customers.

Fraudulent Emails Mimic a Legitimate Vulnerability Warning

Trezor said it had shut down the exploited domain and was investigating how the attackers gained access to the infrastructure used in the campaign.

Security firm PeckShield reported that the phishing sender was spoofed to appear as help@trezor.io.

The malicious correspondence alleged a “critical hardware‑level vulnerability” in STM32 chips, falsely stating that a quarter of Trezor wallets were impacted due to insufficient entropy in private‑key generation— a flaw that, if genuine, could expose seed phrases and jeopardize users’ assets.

Trezor also noted that the phishing email asked recipients to share their wallet backup information.

BitBox Also Warns of Phishing

On the same day, Swiss hardware wallet maker BitBox alerted its users to phishing attempts that impersonated the brand.

BitBox reported that deceptive emails claiming to be from the company were circulating.

Nick Neumann, co‑founder and CEO of Bitcoin self‑custody firm Casa, suggested on X that a shared marketing email provider might have been compromised, potentially affecting Trezor, BitBox and other companies.

ShipMonk Data Breach

The phishing incident follows a separate supply‑chain breach disclosed by Trezor the previous month.

In August 2026, Trezor’s shipping contractor ShipMonk exposed personal data of 80,689 customers. The leaked information primarily comprised names, phone numbers and addresses, while 1,947 customers had only their names, cities and email addresses disclosed.

Why This Matters

Phishing campaigns that masquerade as trusted hardware wallet brands can trick users into revealing recovery phrases or backup data, putting their cryptocurrency holdings at risk. The episodes also underscore the security challenges posed by third‑party vendors that handle customer communications and data.

Source link

Exit mobile version