Trezor confirmed late Wednesday that users were targeted by a convincing phishing campaign after a third-party email provider used by the hardware wallet maker was breached. The company said a fraudulent message titled ‘Critical Security Alert: STM32 Entropy Vulnerability’ was distributed to customers.
Trezor warned users that “Our third-party e-mail provider has been breached,” and advised: “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.” The company said it had taken down the affected domain and is investigating how attackers gained access to infrastructure linked to its legitimate domain. Trezor has not disclosed how many customers received the phishing message.
Trezor phishing bypassed authentication checks
The attack was unusual because the malicious emails were delivered via infrastructure authorized to send email on Trezor’s behalf, making them harder for users and automated filters to detect. A circulating screenshot showed the sender as “Trezor Security” with the address help@trezor.io, and Gmail displayed “mailed-by: mailing.trezor.io” and “signed-by: trezor.io.” The fraudulent messages passed SPF, DKIM, and DMARC checks, which helped explain why recipients saw the “signed-by: trezor.io” indicator and why the emails were less likely to be marked as spam.
Attackers attempted to create urgency by claiming a critical entropy vulnerability in Trezor devices, referencing compromised randomness. The message sought to capitalize on recent panic stemming from an incident that affected Coldcard wallet users earlier this year. Recipients were pushed to follow what appeared to be a security verification process; one Trezor forum user reported that an “offline” HTML file could transmit entered information to Telegram.
Other suspicious emails have been reported targeting customers of BitBox and cryptocurrency portfolio service CoinTracking. Some community investigators have pointed to email marketing provider Brevo as common infrastructure behind the incidents, but Trezor itself has not publicly identified the compromised email provider.
Trezor also disclosed a separate incident in August involving shipping provider ShipMonk that exposed customer information and could increase the risk of targeted phishing. There is currently no confirmed evidence that the ShipMonk exposure and Wednesday’s email-provider compromise were carried out by the same attackers.
The campaign drew sharp reactions on social media. A user tweeting as FatMan (@FatManTerra) wrote: “Really brutal. The phishing email is written quite convincingly, and it comes from the official Trezor domain. At least tens of millions will be lost; hopefully not hundreds of millions. Insane f*ckup from Trezor. https://t.co/GBVcqBEJVh pic.twitter.com/4xw8QM8bvi”

