Trezor Users Targeted in Phishing Campaign After Third-Party Email Provider Breach
Key Takeaways
- •Trezor warned that a phishing email titled 'Critical Security Alert: STM32 Entropy Vulnerability' was sent after a breach at its third-party email provider and did not originate from the company.
- •The fraudulent messages passed standard sender-authentication checks, including DKIM, SPF, and DMARC, because they came from genuinely authorized sending infrastructure associated with the trezor.io domain.
- •The phishing email falsely claimed that approximately one in four Trezor devices contained a factory defect in the random-number generator of their STM32 microcontrollers and pushed recipients to click a link to check their device model.
- •Trezor has taken down the domain used in the attack and is investigating how hackers gained access to its legitimate domain, but has not disclosed the affected email provider or the number of recipients.
- •The phishing campaign follows Trezor's disclosure of unauthorized access at logistics partner ShipMonk, which affected 13,689 users and later an additional 67,000 US customers, though the company has not said whether the two incidents are connected.

Hardware wallet manufacturer Trezor, described as the second-largest producer of devices for storing cryptocurrency, has warned users about a phishing campaign launched after a breach at its third-party email provider. The company confirmed that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” did not originate from Trezor and urged customers not to click any links in the message.
According to a warning posted on X, attackers used the compromised infrastructure to send fraudulent security alerts from a spoofed version of Trezor’s official mailing domain. The messages passed standard sender-authentication checks. Trezor said it had taken down the domain used in the attack and was investigating how the hackers gained access to its legitimate domain. The company has not disclosed the affected provider or the number of recipients.
#PeckShieldAlert @Trezor has reported that their third-party email provider has been breached. A #phishing email titled 'Critical Security Alert: STM32 Entropy Vulnerability' is circulating, spoofing the address help@trezor.io – this is NOT a legitimate Trezor communication. Do… — PeckShieldAlert (@PeckShieldAlert) September 10, 2026
The phishing email was designed to resemble an urgent security notice. It claimed that approximately one in four Trezor devices contained a factory defect in the random-number generator of their STM32 microcontrollers. According to the message, the alleged flaw left wallet seed phrases insufficiently protected against brute-force attacks and required recipients to follow a link to determine whether their device model was affected.
The campaign’s technical credibility may have made it more convincing than conventional phishing attempts. Marcello Paz, one recipient, reported that the email passed Gmail’s sender verification, with DKIM, SPF, and DMARC authentication checks all appearing valid for the trezor.io domain. The message was sent from “Trezor Security” through a Sendinblue campaign, further contributing to its appearance of legitimacy.
The incident illustrates how attackers who compromise trusted communications infrastructure can circumvent the protections typically associated with email authentication. In this case, the fraudulent messages originated from genuinely authorized sending domains rather than from domains merely spoofed by attackers.
Second Security Incident for Trezor in Recent Months
The breach follows a series of security disclosures involving the hardware wallet sector and Trezor. In August, Trezor revealed that its logistics partner ShipMonk had experienced unauthorized access, exposing order information covering the period from May 10 to August 8. The incident affected 13,689 users in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
Personal data was fully compromised for 11,742 customers, while the names, cities, and email addresses of 1,947 others were exposed. On September 4, Trezor disclosed that an additional 67,000 US customers had been affected. Independent estimates indicated that the total impact could exceed 80,000 clients.
Trezor notified affected users about the ShipMonk breach and warned them of an elevated phishing risk. The company has not said whether the two incidents are connected or whether customer data obtained in the logistics breach was used to target recipients of the current campaign. Further updates on the email provider, the number of recipients, and the ongoing investigation would clarify the scope of the campaign and whether it overlaps with the earlier exposure.
Users should treat emails requesting clicks or personal information with caution and verify security notices directly through official Trezor channels rather than through embedded links. Trezor’s official website is The warning was also discussed in this X post: https://x.com/PeckShieldAlert/status/2097863078406930739?ref_src=twsrc%5Etfw.