Crypto World
Trezor Issues Security Warning After Third-Party Security Breach
Trezor has warned that a third-party security breach enabled phishing emails to be sent out from the hardware wallet provider’s official domain.
The breach comes soon after a security incident at ShipMonk compromised the personal information of Trezor users.
Trezor Warns Of Third-Party Breach
Trezor issued a warning in an official X post, informing users that the email “Critical Security Alert: STM32 Entropy Vulnerability” was a phishing attempt and urged them to avoid clicking any links.
“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”
The compromised domain has since been taken down, and Trezor has launched a full investigation into the breach and how hackers used the company’s official domain to send phishing emails. Marcello Paz, a crypto commentator, said he received the phishing email in question and shared screenshots asking customers to update their hardware wallets due to a “critical vulnerability.” Unlike typical phishing emails, the email’s credentials showed official domain names and signatures.
“Hello @trezor, I received a “Critical Security Alert: STM32 Entropy Vulnerability” email today (9 Sep 2026). Gmail shows From: Trezor Security , Return-Path: noreply@mailing.trezor.io, Sendinblue campaign, DKIM/SPF/DMARC pass for trezor.io. Body claims a factory STM32 RNG defect (~1 in 4 devices), ~40-bit seeds, and a “check if you’re affected” link via r.mailing.trezor.io plus xPub verification. This matches the entropy-phishing wave, not any official advisory.”
Similar Attempt On BitBox
BitBox, a Swiss Bitcoin hardware wallet maker, reported a similar phishing attempt. The company shared a similar email on its official X account, warning users it was a phishing attempt and urged them to be cautious.
“There is currently a phishing email going around that’s pretending to come from us. Please do not follow the instructions in the email! We are currently investigating.”
Previous Security Incidents
Last month, Trezor’s shipping provider ShipMonk was hit by a major security breach that exposed personal information linked to its customers. Trezor initially disclosed that personal information, including names, cities, and email addresses of 13,700 users, was compromised. However, it said another 67,000 US-based users were affected by the breach.
Hardware wallets have been hit by several security vulnerabilities and breaches recently. Ledger’s security team disclosed a major vulnerability in Trezor Safe 7’s TROPIC01 chip, demonstrating how a lab-based laser attack bypassed its firmware verification system. Ledger suffered a major security breach in 2020 that exposed the personal information of over 270,000 customers, including names, email addresses, phone numbers, and even home addresses. The details were published on a dark web forum, with impacted customers receiving scam calls and physical letters even years later.
Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.
You must be logged in to post a comment Login