Trezor Email Provider Breach Used to Send STM32 Phishing Alerts

yesterday / 23:11 3 sources negative

Key takeaways:

  • Phishing via Trezor's legitimate email underscores growing attacks on hardware wallet trust.
  • Expect more supply chain email compromises as attackers target crypto infrastructure intermediaries.
  • User vigilance post-Coldcard breach is critical; verify all security alerts independently.

Trezor has confirmed that attackers breached its third-party email provider and used the company’s legitimate domain to distribute phishing emails titled “Critical Security Alert: STM32 Entropy Vulnerability.” The hardware wallet maker warned users on X that the message is not from Trezor and urged them not to click any link.

The fraudulent email falsely claimed that Trezor engineers had discovered a critical hardware-level vulnerability in STM32 microcontrollers used in its devices. It alleged that the defect affected roughly one in four devices and could leave recovery phrases with insufficient randomness, or entropy. According to researchers, the messaging likely played on fears related to the recent Coldcard exploit, which reportedly cost users more than $130 million in Bitcoin.

Trezor said it took down the domain used in the attack and is investigating how hackers gained access to its legitimate email infrastructure. The company issued its warning just after 4:30 p.m. Eastern Time on Wednesday, hours after several users reported receiving the phishing scam from what appeared to be a legitimate Trezor email address.

Casa co-founder and CEO Nick Neuman said the campaign may extend beyond Trezor, adding that he had heard similar reports from BitBox users. “It’s likely that a marketing email provider was compromised,” Neuman said. Bitcoin security researcher Jameson Lopp echoed that warning, saying threat actors may have compromised email providers used by both Trezor and BitBox. He noted that the malicious emails do not appear to be spoofed and that no such security advisory has been issued.

The incident follows a series of hardware wallet security concerns. In August, Trezor and Foundation warned users about phishing attempts exploiting hardware wallet security fears after researchers disclosed vulnerabilities affecting Coldcard devices. That same month, Trezor reported that a breach at shipping provider ShipMonk exposed customer data belonging to 80,689 people, including names, email addresses, phone numbers, and shipping addresses, and warned that the leaked information could be used in more sophisticated phishing attacks.

Previously on the topic:
Sep 4, 2026, 8:16 p.m.
XRP Healthcare Halts XRPH Wallet Use After Unauthorized Transactions
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.