NG Solution Team
Cybersecurity

Trezor Users Targeted via Compromised Email Service

Hackers breached a third-party email service used by Trezor on September 9, 2026, sending users a fake security alert claiming an STM32 entropy vulnerability in the hardware wallets. Trezor warned on Twitter: “Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating…”.

The phishing messages were sent from an address displayed as Trezor Security with the subject line “Critical Security Alert: STM32 Entropy Vulnerability,” alleging a critical issue with random data generation in STM32 microcontrollers. One recipient, Marcello Paz, reported that Gmail showed the message as From: Trezor Security, Return-Path noreply@mailing.trezor.io, identified a Sendinblue campaign and that DKIM/SPF/DMARC checks passed.

The fraudulent email claimed roughly one in four devices suffered a factory defect in the random number generator, leaving wallet seed phrases vulnerable to brute-force attacks, and urged recipients to follow a link to check whether their model was affected.

Trezor response and investigation

Trezor said it has disabled the domain used in the attack and is investigating the incident. The company has not disclosed the name of the breached provider or how many recipients received the phishing message. Experts are examining the breach, including how attackers gained access to the email provider’s infrastructure.

BitBox users also affected

BitBox reported a similar phishing campaign affecting its clients. The BitBox team said several other Bitcoin companies have been targeted by similar attacks and that it appears they all use the same email provider. Developers said they sent a phishing warning to newsletter subscribers, contacted the provider and reported the fake domains, and that most fake links have since been removed.

In August, Trezor disclosed a separate breach of a contractor, the logistics company ShipMonk, which the team said affected over 80,000 clients.

Related posts

Heathrow and Gatwick: Check flights after air traffic control issue

Michael Johnson

US Embassy in Bahrain Issues Security Alert, Urges Vigilance

Emily Brown

Amgen data breach: were patient records stolen?

Jessica Williams

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy