Hardware wallet maker Trezor warned users on September 9, 2026, after hackers breached its third-party email provider to send highly convincing phishing emails from its official domain. The fraudulent emails claimed a fake 'STM32 Entropy Vulnerability' existed in Trezor devices, attempting to trick users into exposing their recovery phrases. Swiss competitor BitBox suffered a matching campaign the same day, indicating a broader compromise of shared marketing email infrastructure. This incident marks Trezor's third vendor-related security failure in four weeks, following a ShipMonk shipping breach that exposed over 80,000 customer records.
Story comments
Loading comments…