Trezor Says Hackers Breached Email Provider to Send Phishing Alert
Key Takeaways
- •Hackers compromised a third-party email provider used by Trezor and sent phishing emails disguised as an urgent advisory about an STM32 microcontroller vulnerability.
- •Trezor confirmed the 'Critical Security Alert: STM32 Entropy Vulnerability' email was fraudulent and urged users not to click any links, stating the alleged flaw affecting an estimated one in four devices does not exist.
- •The company took down the domain used in the attack and is investigating how hackers gained access to its legitimate sending domain.
- •Casa executives Nick Neuman and Jameson Lopp warned the campaign could extend to BitBox users, noting the messages passed DKIM, SPF, and DMARC checks and did not appear spoofed.
- •The phishing wave followed an August incident in which a ShipMonk breach exposed data of 80,689 Trezor customers, information the company warned could enable more sophisticated attacks.

Trezor said hackers breached its third-party email provider and used the service to distribute phishing emails disguised as a critical security warning. The fraudulent alert falsely claimed that a hardware flaw weakened recovery phrases on some Trezor devices.
The company warned users on Wednesday that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” did not come from Trezor. “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” Trezor wrote on X.
Trezor said it had taken down the domain used in the attack and was investigating how the hackers gained access to its legitimate domain. The email falsely claimed that Trezor engineers had discovered a “critical hardware-level vulnerability” in STM32 microcontrollers used in the company’s devices. It further alleged that the defect affected an estimated one in four devices and could leave recovery phrases with insufficient randomness, or entropy.
The claim appeared designed to exploit concerns raised by a recent Coldcard exploit that cost users over $130 million in Bitcoin. Trezor issued a statement calling the email fraudulent and warning users just after 4:30 p.m. Easter Time, hours after several users reported receiving the phishing message from what appeared to be a legitimate Trezor email address.
Casa co-founder and CEO Nick Neuman said the campaign could extend beyond Trezor, adding that he had heard similar reports from BitBox users. “It’s likely that a marketing email provider was compromised,” Neuman said on X. “Stay frosty and don't trust provider emails that try to get you to take actions via sketchy looking links.”
One user, Marcello Paz, posted details of the message on X on September 9, 2026. He said Gmail displayed the sender as Trezor Security help@trezor.io, with a return path of noreply@mailing.trezor.io. He also said the message identified a Sendinblue campaign and showed DKIM, SPF, and DMARC as passing for His post included the campaign’s tracking link and the URL Marcello Paz on X.
The reported sender details and authentication checks could make the message appear legitimate to recipients, but they did not make its security claim genuine. Users should verify advisories through a company’s official channels rather than relying on links in an email.
Bitcoin security researcher and Casa Chief Security Officer Jameson Lopp issued a similar warning. “Threat actors may have compromised the email provider(s) used by Trezor and BitBox,” he wrote on X. “Malicious emails claiming both have bad RNGs that require security updates are being sent, and the emails don't appear to be spoofed. No such security advisory has been issued!”
In August, Trezor and fellow crypto hardware-wallet maker Foundation warned users about phishing attempts that exploited fears about hardware-wallet security after researchers disclosed vulnerabilities affecting Coldcard devices.
That same month, Trezor reported that a breach at shipping provider ShipMonk exposed customer data belonging to 80,689 people, including names, email addresses, phone numbers, and shipping addresses. The company warned that the leaked information could be used in more sophisticated phishing attacks. Trezor’s report is available in its official announcement.