Hardware wallet manufacturer Trezor has warned users about a phishing campaign after attackers breached a third-party email provider and distributed fraudulent security alerts that appeared to come from the company.
Trezor disclosed the incident Wednesday after customers began receiving an email titled “Critical Security Alert: STM32 Entropy Vulnerability.” The message falsely claimed that a serious hardware problem could put users' recovery phrases at risk.
The company quickly told users not to interact with the email.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
— Trezor (@Trezor) September 9, 2026
We have taken down the domain, and we are investigating…
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
— Trezor (@Trezor) September 9, 2026
We have taken down the domain, and we are investigating…
Trezor said it had taken down the domain associated with the attack and launched an investigation into how attackers gained access to infrastructure capable of sending messages that appeared legitimate.
Phishing Email Claims Hardware Vulnerability
The fraudulent email claimed Trezor engineers had discovered a critical vulnerability involving STM32 microcontrollers used inside its hardware wallets.
Attackers falsely alleged that approximately one in four devices could be affected by insufficient randomness, or entropy, potentially weakening the recovery phrases protecting cryptocurrency holdings.
The claims appear designed to exploit heightened anxiety surrounding hardware wallet security following the recent Coldcard exploit, which reportedly resulted in more than $130 million in Bitcoin losses.
Trezor emphasized that no such security advisory had been issued.
The warning arrived several hours after users first reported receiving the phishing messages from what appeared to be legitimate Trezor email addresses, making the campaign potentially more convincing than ordinary spoofed phishing emails.
BitBox Users May Also Have Been Targeted
The incident may extend beyond Trezor.
Casa co-founder and CEO Nick Neuman said he had heard reports of similar emails being received by BitBox users, raising the possibility that attackers compromised infrastructure shared by multiple cryptocurrency companies.
There are convincing phishing emails going out right now from hardware wallet companies (have heard Trezor and Bitbox at least). It's likely that a marketing email provider was compromised. That will mean more customer emails are leaked.
— Nick Neuman (@Nneuman) September 9, 2026
Stay frosty and don't trust provider… pic.twitter.com/jHtdRE9S2A
There are convincing phishing emails going out right now from hardware wallet companies (have heard Trezor and Bitbox at least). It's likely that a marketing email provider was compromised. That will mean more customer emails are leaked.
— Nick Neuman (@Nneuman) September 9, 2026
Stay frosty and don't trust provider… pic.twitter.com/jHtdRE9S2A
Neuman urged users to remain suspicious of provider emails directing them toward unfamiliar links, even when the sender initially appears legitimate.
Bitcoin security researcher and Casa Chief Security Officer Jameson Lopp issued a similar warning, saying threat actors may have compromised email providers used by both Trezor and BitBox.
Lopp noted that malicious messages were claiming both hardware wallets suffered from defective random number generation and required security updates. Importantly, he said the emails did not appear to be conventional spoofed messages.
Hardware Wallet Phishing Attacks Increase
The latest incident comes amid a broader increase in phishing campaigns exploiting fears about cryptocurrency hardware wallet vulnerabilities.
In August, Trezor and fellow hardware wallet manufacturer Foundation warned customers about phishing attempts that emerged after security researchers disclosed vulnerabilities involving Coldcard devices.
Attackers can use legitimate security news as social engineering material, creating fake warnings that pressure users into taking immediate action.
For hardware wallet owners, such campaigns are particularly dangerous because recovery phrases provide complete control over the assets associated with a wallet. A phishing website that successfully obtains one can allow attackers to drain funds without needing physical access to the device.
Trezor Faced Separate Customer Data Breach in August
The email incident also follows another security problem involving one of Trezor's external service providers.
In August, Trezor disclosed that a breach affecting shipping provider ShipMonk exposed information belonging to 80,689 customers.
The compromised information included names, email addresses, telephone numbers and shipping addresses. Trezor warned at the time that the leaked information could potentially be used to create more convincing and personalized phishing attacks against hardware wallet owners.
The latest campaign illustrates how third-party infrastructure can become an important attack vector even when the hardware wallet itself has not been compromised.
Trezor has not reported a vulnerability in its devices related to the phishing email's claims. Instead, the company is investigating the breach of its email provider while urging customers to avoid links in the fraudulent security alert.
For users, the incident reinforces a fundamental hardware wallet security rule: a recovery phrase should never be entered into a website or shared in response to an email, regardless of how convincing the warning appears.



