Trezor Warns Customers of Phishing After External Email Provider Breach

Views: 31 views

500/69 Friday, September 11, 2026

Trezor, a cryptocurrency hardware wallet manufacturer, has warned customers after attackers compromised an external email provider used by the company and abused it to send phishing emails to customers. The fake emails used subject lines such as “Critical Security Alert” and claimed that a vulnerability had been found in the hardware microcontroller, or STM32 microcontroller, used in Trezor cold storage wallets, which could allow users’ seeds to be brute-forced. Trezor confirmed that these emails were not sent by the company and were a scam attempt designed to trick users into clicking malicious links.

Trezor stated that it is currently investigating the incident, including how the attackers were able to access the company’s legitimate domain. The company also said it has disabled the domain used in the attack to stop the phishing emails from spreading. Trezor warned users not to click any links in emails referring to an “STM32 Entropy Vulnerability” or security alerts that do not come directly from Trezor’s official channels, as they may lead to fake websites designed to steal sensitive information or cryptocurrency wallet seed phrases.

The incident follows a data breach Trezor disclosed in August 2026 involving its third-party shipping and logistics provider, ShipMonk, which was compromised and resulted in the theft of customer order information, including full names, shipping addresses, email addresses, and phone numbers. The number of affected individuals later increased to 81,000, including customers in the United States, Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026. Reports also indicated that the incident was linked to the exploitation of a SQL Injection zero-day vulnerability in the Metabase platform to gain administrator privileges and steal data. ShipMonk also reportedly received an extortion email from the ShinyHunters group following the breach.

Source: https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/