Trezor has warned customers that a phishing email was sent after attackers breached one of its third-party email providers. The company says the message, which falsely warns of a major Trezor wallet security risk, is not genuine and advises recipients not to click any links.
The phishing email used the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” Clicking links in the message may lead to sites asking for confidential wallet details. In a post, Trezor said: “The email…is not coming from us, and it’s a phishing attempt.” The company has taken down the domain involved and is investigating how the attackers gained access to a legitimate domain.
Because the message originated from a genuine domain, some users may be convinced it is real. Trezor noted that while attentive users often check the sender address, a fraudulent message coming from an original domain can appear authentic.
Trezor has not revealed the name of the affected email provider, nor has it disclosed how many customers received the fraudulent message or whether their details were accessed. The firm also said it has not reported any loss of cryptocurrency due to this campaign.
Trezor and a separate third-party breach
Weeks earlier, Trezor experienced a separate breach involving its shipping provider, ShipMonk, which exposed names, email addresses, phone numbers and delivery addresses. Trezor later said 67,000 more customers have also been affected in the US. The company said the recent phishing campaign did not originate from ShipMonk and has neither attributed the two incidents to one another nor claimed they share the same attackers.
Customers who received the fraudulent email should avoid its links and delete the message. Trezor also reminded users never to enter their wallet backup on a website or share it with anyone.

