Crypto World

Trezor Issues Security Warning After Third-Party Security Breach

Published

on

Trezor has warned that a third-party security breach enabled phishing emails to be sent out from the hardware wallet provider’s official domain.

The breach comes soon after a security incident at ShipMonk compromised the personal information of Trezor users.

Trezor Warns Of Third-Party Breach

Trezor issued a warning in an official X post, informing users that the email “Critical Security Alert: STM32 Entropy Vulnerability” was a phishing attempt and urged them to avoid clicking any links.

“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”

Advertisement

The compromised domain has since been taken down, and Trezor has launched a full investigation into the breach and how hackers used the company’s official domain to send phishing emails. Marcello Paz, a crypto commentator, said he received the phishing email in question and shared screenshots asking customers to update their hardware wallets due to a “critical vulnerability.” Unlike typical phishing emails, the email’s credentials showed official domain names and signatures.

“Hello @trezor, I received a “Critical Security Alert: STM32 Entropy Vulnerability” email today (9 Sep 2026). Gmail shows From: Trezor Security , Return-Path: noreply@mailing.trezor.io, Sendinblue campaign, DKIM/SPF/DMARC pass for trezor.io. Body claims a factory STM32 RNG defect (~1 in 4 devices), ~40-bit seeds, and a “check if you’re affected” link via r.mailing.trezor.io plus xPub verification. This matches the entropy-phishing wave, not any official advisory.”

Similar Attempt On BitBox

BitBox, a Swiss Bitcoin hardware wallet maker, reported a similar phishing attempt. The company shared a similar email on its official X account, warning users it was a phishing attempt and urged them to be cautious.

“There is currently a phishing email going around that’s pretending to come from us. Please do not follow the instructions in the email! We are currently investigating.”

Advertisement

Previous Security Incidents

Last month, Trezor’s shipping provider ShipMonk was hit by a major security breach that exposed personal information linked to its customers. Trezor initially disclosed that personal information, including names, cities, and email addresses of 13,700 users, was compromised. However, it said another 67,000 US-based users were affected by the breach.

Hardware wallets have been hit by several security vulnerabilities and breaches recently. Ledger’s security team disclosed a major vulnerability in Trezor Safe 7’s TROPIC01 chip, demonstrating how a lab-based laser attack bypassed its firmware verification system. Ledger suffered a major security breach in 2020 that exposed the personal information of over 270,000 customers, including names, email addresses, phone numbers, and even home addresses. The details were published on a dark web forum, with impacted customers receiving scam calls and physical letters even years later.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version