Trezor warned its customers on September 9 that a phishing email carrying the subject line “Critical Security Alert: STM32 Entropy Vulnerability” did not come from the company, even though it arrived from Trezor’s genuine email address. The hardware-wallet maker said its third-party email provider had been breached, in a post on X, and that it had taken down the domain and was investigating how attackers used its legitimate infrastructure. The reassurance holders need first: this was a breach of the email channel, not of Trezor’s devices, so the private keys and recovery phrases stored on wallets were not extracted, and the STM32 flaw the email describes does not exist.
What makes this attack more dangerous than ordinary phishing is that it defeats the standard advice given to wallet owners. The usual tell, a lookalike sender address, is absent here, because the message genuinely came from Trezor’s own mailing system.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
— Trezor (@Trezor) September 9, 2026
Why the STM32 Phishing Email Worked
The email was engineered to trigger the exact fear that makes a careful person act against their own interest. It claimed Trezor engineers had found a critical hardware vulnerability in the STM32 microcontrollers used in its devices, one that supposedly left recovery phrases with insufficient randomness, or entropy, on an estimated one in four devices. That framing is designed to make a holder rush to “fix” their wallet by entering their recovery phrase somewhere it can be stolen.
The claim is false: Trezor confirmed there is no such defect, and its devices generate at least 128-bit entropy by default. The bait also leaned on genuine recent anxiety, following a Coldcard firmware flaw that FinanceFeeds reported was linked to more than $130 million in stolen Bitcoin earlier this year.
The delivery is what let it past spam filters. Because the message travelled through Trezor’s real newsletter infrastructure rather than a spoofed domain, it displayed help@trezor.io as the sender and passed the standard authentication checks, so services like Gmail treated it as legitimate. A holder checking the sender address, the first thing security guides tell them to do, would have seen nothing wrong.
Investor Takeaway
The breach hit the email channel, not the wallets: Trezor’s devices were not compromised and no keys were extracted, so a holder who did not act on the email has nothing to fix.
What Trezor Says Was and Was Not Exposed
Trezor’s statements describe a compromise of its external email provider, which gave attackers a channel to send authenticated-looking phishing, rather than any access to its own systems or hardware. The company said it deactivated the malicious domain and is investigating how its official domain was used.
No confirmed cryptocurrency losses have been tied to the campaign as of publication, and the STM32 vulnerability at the center of the email is fabricated. The one thing holders must not do is treat the email’s authenticity, its real sender address and clean authentication, as evidence that its contents are true.
The ShipMonk Breach Five Days Earlier, and the BitBox Signal
This is Trezor’s second third-party exposure in about a month. On September 4, FinanceFeeds reported that a breach at Trezor’s shipping provider ShipMonk had exposed the personal data of around 67,000 more customers, bringing the total near 80,000, with names, emails, phone numbers and addresses among the leaked records. That earlier leak matters here because it hands attackers exactly the contact details needed to make phishing feel personal, part of a wider run of third-party breaches hitting the sector that includes a Ledger customer-data exposure through its provider Global-e and a Pocket Bitcoin breach affecting more than 5,400 customers.
The email attack may not be Trezor’s alone. Swiss rival BitBox reported an almost identical phishing email reaching its own subscribers the same day and said its preliminary review found it “very likely that our newsletter provider got compromised,” with several Bitcoin companies appearing to share the same platform.
Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised.
Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider.
We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains. Most of the phishing links appear to have been taken down already.
We are still actively investigating this situation and will update you once we know more.
— BitBox (@BitBoxSwiss) September 9, 2026
Casa co-founder Nick Neuman and the firm’s chief security officer, the Bitcoin security researcher Jameson Lopp, both said on X that the messages did not resemble ordinary spoofing, with Neuman writing that “it’s likely that a marketing email provider was compromised.” That remains a hypothesis rather than a confirmed finding, but with two named executives and a second affected company describing the same shared-provider pattern, the exposure looks more like an industry-wide supply-chain problem than a single vendor’s lapse.
There are convincing phishing emails going out right now from hardware wallet companies (have heard Trezor and Bitbox at least). It’s likely that a marketing email provider was compromised. That will mean more customer emails are leaked.
Stay frosty and don’t trust provider… pic.twitter.com/jHtdRE9S2A
— Nick Neuman (@Nneuman) September 9, 2026
What a Trezor Holder Should Do Now
The safe response is the boring one. Do not click any link in the STM32 email, do not enter your recovery phrase anywhere in response to it, and verify any genuine security notice through the official Trezor Suite application rather than an email link, which mirrors the guidance FinanceFeeds set out when mail-based phishing hit Ledger and Trezor owners earlier this year.
A recovery phrase should never be typed into a website or app under any circumstances, because no legitimate firmware update or security fix requires it. If you received the email but did nothing, your wallet is unaffected. If you clicked through and entered your seed, move your funds to a new wallet with a newly generated recovery phrase immediately, and treat the old one as compromised.
Investor Takeaway
The channel is the weak point, not the wallet: this breach and the ShipMonk leak both hit third-party vendors, so the lesson for holders is to distrust the delivery channel, since even a real sender address no longer guarantees a real message.






