Trezor Users Targeted By Phishing Emails After Provider Breach
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Trezor warned users after hackers used phishing emails to spread a fake security alert.
- The attack involved a compromised email provider that hackers used to reach Trezor customers.
- Trezor urged users to avoid suspicious links in emails claiming to require security updates.
Trezor, a hardware maker, confirmed that hackers breached its third-party email provider and used it to send phishing emails. The attackers targeted Trezor users with a fake security alert about an alleged hardware wallet vulnerability. Trezor warned users Wednesday not to click links or follow instructions in the fraudulent message.
Second-Largest Hardware Wallet Maker Trezor Warns of Phishing Email After Third-Party Email Provider Breach
Trezor said its third-party email provider has been breached. The company warned that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” did not come… pic.twitter.com/XVhRZZ4enV
— Wu Blockchain (@WuBlockchain) September 9, 2026
The phishing email carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” The message falsely claimed that Trezor engineers had discovered a critical vulnerability in STM32 microcontrollers. It claimed that the alleged flaw affected about one in four Trezor devices. The attackers also claimed that the issue could weaken the randomness of wallet recovery phrases.
Trezor confirmed that attackers created the message as a phishing attempt. The company said it had not issued any security advisory about an STM32 entropy vulnerability. Trezor also took down the domain that attackers used during the campaign. The company is investigating how hackers gained access to its third-party email provider.
Several users reported receiving the fraudulent email before Trezor issued its public warning. The attackers made the message appear credible by using technical claims about wallet security. They also used a trusted email channel to reach potential victims. The campaign attempted to push users toward links through an urgent security warning.
Trezor Phishing Emails Carry Fake Security Warning
The attackers built their false warning around concerns from a real Coldcard security incident. The Coldcard vulnerability involved weak random number generation during wallet seed creation. Attackers later identified wallets that had received vulnerable seeds and stole Bitcoin from the affected addresses. The incident made wallet entropy a major security concern for hardware wallet users.
The fake Trezor message used those concerns to make its claims appear credible. The attackers warned that weak entropy could leave recovery phrases vulnerable to theft. They then directed recipients toward a link that supposedly offered a security update. Trezor told users to ignore the message because the company had issued no such update.
Casa co-founder Nick Neuman also warned users about the phishing campaign. He suggested that the campaign could involve companies beyond Trezor.
Hello @trezor,
I received a “Critical Security Alert: STM32 Entropy Vulnerability” email today (9 Sep 2026).
Gmail shows From: Trezor Security <[email protected]>, Return-Path [email protected], Sendinblue campaign, DKIM/SPF/DMARC pass for https://t.co/69NqnLtwGr.
Body… pic.twitter.com/jKsngEyKXS
— Marcello Paz (@MHPaz) September 9, 2026
Meanwhile, Jameson Lopp, the Chief Security Officer at Casa, issued a similar warning on Wednesday. He said attackers had sent emails claiming that Trezor and BitBox had random number generation problems. Lopp said, “Malicious emails claiming both have bad RNGs that require security updates are being sent, and the emails don’t appear to be spoofed. No such security advisory has been issued!”
Trezor Incident Follows Similar BitBox Breach
Trezor had already warned customers about a separate third-party data breach in August. The breach at shipping provider ShipMonk exposed information linked to 80,689 Trezor customers. The exposed information included names, email addresses, phone numbers, and shipping addresses. Trezor warned that criminals could use the data to create more convincing phishing attacks.
Trezor has not linked the latest email provider breach to the earlier ShipMonk incident. The company has also urged users to verify security messages through its official channels.
In a related development, BitBox warned customers Wednesday after attackers sent phishing emails impersonating the company. BitBox said its preliminary investigation indicated that attackers had compromised its newsletter provider. The company said several Bitcoin businesses appeared to use the same provider. BitBox said the shared provider could explain why similar phishing messages reached customers of different companies.
There is currently a phishing email going around that's pretending to come from us.
Please do not follow the instructions in the email!
We are currently investigating. https://t.co/vKK4VxYPm3
— BitBox (@BitBoxSwiss) September 9, 2026
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







