Trezor confirmed on September 10, 2026, that its third-party email provider fell victim to a breach, allowing hackers to dispatch phishing emails masquerading as legitimate communications from the well-known hardware wallet manufacturer.
The fraudulent email, bearing the ominous title “Critical Security Alert: STM32 Entropy Vulnerability,” falsely claimed that a hardware flaw in Trezor devices could compromise the randomness of users’ recovery phrases. This alarming message aimed to coerce users into updating their devices under the pretense of safeguarding their assets.
In a prompt response on X, Trezor cautioned users: “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.” The company swiftly took down the compromised domain and initiated an investigation to determine how the breach occurred.
The timing of the phishing attack appears calculated, attempting to exploit heightened concerns surrounding a recent Coldcard vulnerability that reportedly resulted in losses exceeding $130 million for users.
BitBox Users Also Targeted
Further complicating the situation, Swiss hardware wallet manufacturer BitBox reported that its users received similar phishing emails on the same day as Trezor’s incident. This raises alarms that the attack may extend beyond Trezor to other hardware wallet providers.
Casa CEO Nick Neuman speculated that the breach could stem from a shared email marketing provider, advising users to “stay frosty and don’t trust provider emails that try to get you to take actions via sketchy looking links.” Security experts like Jameson Lopp, Casa’s Chief Security Officer, echoed these sentiments, cautioning that the phishing emails were not merely spoofed but sent from actual addresses.
Crypto commentator MHPaz shared screenshots of the fraudulent email, which appeared convincingly authentic, further highlighting the sophistication of the attack.
A Pattern of Breaches
This incident is not Trezor’s first brush with security issues in recent months. Last month, a data breach at shipping provider ShipMonk compromised the personal information of over 80,000 Trezor customers, including names, emails, and shipping addresses. At that time, Trezor had warned that the leaked data could be exploited in targeted phishing attacks, a caution that now seems prescient.
In June, a vulnerability was also disclosed in the TROPIC01 chip used in the Trezor Safe 7, although Trezor assured users that their funds remained secure.
As a precaution, hardware wallet users are advised against clicking any links in emails concerning security alerts from wallet providers until further notice. It’s crucial to verify such alerts directly on the official website.
At this time, there have been no confirmed reports of funds lost as a result of the ongoing phishing campaign.
