Trezor has confirmed that a third-party email provider was compromised and used to distribute a phishing campaign targeting hardware wallet customers. The fraudulent emails carried the subject “Critical Security Alert: STM32 Entropy Vulnerability” and attempted to convince recipients that their wallet recovery seeds were at risk. Trezor said its hardware wallets themselves were not identified as compromised in the incident.
In its official security warning, Trezor told users not to click links contained in the message and said it had taken down the domain involved while investigating how attackers gained access through its legitimate email infrastructure. Because the campaign was sent through a compromised provider rather than simple address spoofing, the emails could appear considerably more authentic to recipients.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating…
— Trezor (@Trezor) September 9, 2026
Phishing Campaign Targets Recovery Seeds
The malicious message falsely claimed that an entropy flaw involving STM32 microcontrollers could make Trezor recovery seeds vulnerable to brute-force reconstruction. Trezor explicitly rejected the warning as fraudulent, reinforcing its standing guidance that the company will never ask customers to enter, verify or disclose their wallet backup through a website or unsolicited communication.
Reports from affected users indicate that the phishing flow attempted to direct victims toward a page or downloaded file designed to collect recovery-seed information. Anyone who disclosed a valid wallet backup could face direct loss of funds because possession of the seed is sufficient to reconstruct control over the associated wallet. Simply receiving the email, however, does not compromise a hardware wallet.
The incident illustrates a recurring security problem for self-custody products: attackers do not necessarily need to defeat hardware protections if they can compromise communication channels and convince users to surrender credentials voluntarily. Third-party infrastructure can therefore become part of the attack surface even when private keys remain securely isolated inside the device.
ShipMonk Link Remains Unconfirmed
The latest phishing campaign follows a separate breach involving Trezor fulfillment provider ShipMonk. Trezor said that incident ultimately exposed customer information belonging to 80,689 people, including combinations of names, email addresses, phone numbers and shipping addresses. Trezor has not established that the ShipMonk data was used in the new email-provider attack, so the two incidents should be treated separately unless the company confirms a connection.
The ShipMonk breach nevertheless increases the broader phishing risk around affected customers because exposed contact information can be used to create more convincing targeted messages. Trezor previously warned that leaked customer data could support fraudulent emails, calls, letters and impersonation attempts, while stressing that its devices and internal systems were not compromised in that incident.
The operational rule remains straightforward: never enter a recovery seed in response to an email, web link or unsolicited security warning. The current incident is a compromise of communications infrastructure, not evidence of a newly confirmed vulnerability in Trezor hardware, and the company’s investigation into the third-party provider remains ongoing.
Natalie Pierce tracks the parts of crypto that move fast and rarely wait for everyone to catch up. From South Africa, she covers DeFi, AI crypto, hacks, airdrops, sentiment and emerging narratives, especially when user behavior and protocol risk start to overlap.
Her reporting is built for messy sectors. Natalie looks at incentives, reactions, security concerns, social momentum and early signs of traction without pretending every new trend is already proven. Her voice is clear and accessible, but careful enough for areas where excitement can outrun the facts very quickly.
