Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Trezor warns users after hackers breach third-party email provider to send phishing emails
00

Trezor warns users after hackers breach third-party email provider to send phishing emails

Sep 9, 2026

Hardware wallet maker Trezor warned users on September 9, 2026, after hackers breached its third-party email provider to send highly convincing phishing emails from its official domain. The fraudulent emails claimed a fake 'STM32 Entropy Vulnerability' existed in Trezor devices, attempting to trick users into exposing their recovery phrases. Swiss competitor BitBox suffered a matching campaign the same day, indicating a broader compromise of shared marketing email infrastructure. This incident marks Trezor's third vendor-related security failure in four weeks, following a ShipMonk shipping breach that exposed over 80,000 customer records.

Third-party email provider breach

  • ▪The breach of Trezor's third-party email provider represents the company's third vendor-related security failure within a four-week period.
  • ▪Hardware wallet maker Trezor announced on September 9, 2026, that its third-party email provider had been breached, allowing attackers to send phishing emails from Trezor's official domain.

Fake STM32 vulnerability phishing

  • ▪The fraudulent email sent to Trezor users carried the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' and claimed that a design defect in STM32 microcontrollers weakened device recovery phrases.
  • ▪The phishing email sent to Trezor users successfully passed DKIM, SPF, and DMARC authentication checks and followed the Sendinblue campaign path from a legitimate sending address.
  • ▪The fake security alert falsely claimed that the STM32 microcontroller defect affected approximately one in four Trezor devices, mimicking language from a recent Coldcard exploit.

Trezor investigation response

  • ▪Trezor took down the domain used in the phishing campaign and launched an investigation into how attackers accessed its legitimate sending infrastructure.
  • ▪Trezor issued a public warning on September 9, 2026, advising users not to click any links in the fraudulent email and reiterating that users should never share their wallet backup phrases.

BitBox similar phishing campaign

  • ▪Swiss hardware wallet maker BitBox reported a matching phishing campaign targeting its newsletter subscribers on September 9, 2026, which also impersonated the company with fake security warnings.
  • ▪Casa co-founder Nick Neuman and Chief Security Officer Jameson Lopp stated that the simultaneous campaigns suggest a shared marketing or newsletter email provider used by both Trezor and BitBox was compromised.

ShipMonk shipping provider breach

  • ▪Trezor disclosed on August 13, 2026, that a security breach at its shipping provider, ShipMonk, exposed the personal information of 13,689 customers.
  • ▪A September 4, 2026, update from Trezor revealed that the ShipMonk breach affected an additional 67,000 U.S. customers, bringing the total number of exposed customer records to 80,689.

Debatable claims

  • ▪Frequent third-party data leaks undermine the security value of hardware wallets
  • ▪Hardware wallet companies should be held legally liable for data breaches at their third-party vendors

5 sources

Unchainedcrypto
Trezor Says Third-Party Email Breach Let Attackers Send Phishing From Its Own Domain - Unchained
View source article
Beincrypto
Trezor Reports Another Security Incident: What Users Should Know
View source article
Decrypt
Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider - Decrypt
View source article
Cryptopolitan
Trezor phishing shows attackers can skip the device and target the human trust layer - Cryptopolitan
View source article
The Block
Trezor says third-party security breach led to phishing emails from legitimate domain
View source article

Story comments

Loading comments…

Related Projects

Trezor

Topics

Phishing attacksHardware walletsCrypto securityBitcoin wallets & custody