Thursday, September 10, 2026

Trezor Warns of Email Provider Breach

Photorealistic close-up of a hardware wallet under soft neutral lighting, signaling phishing risk from a compromised email provider.

Trezor Warns of Email Provider Breach

Trezor has confirmed that a third-party email provider was compromised and used to distribute a phishing campaign targeting hardware wallet customers. The fraudulent emails carried the subject “Critical Security Alert: STM32 Entropy Vulnerability” and attempted to convince recipients that their wallet recovery seeds were at risk. Trezor said its hardware wallets themselves were not identified as compromised in the incident.

In its official security warning, Trezor told users not to click links contained in the message and said it had taken down the domain involved while investigating how attackers gained access through its legitimate email infrastructure. Because the campaign was sent through a compromised provider rather than simple address spoofing, the emails could appear considerably more authentic to recipients.

Phishing Campaign Targets Recovery Seeds

The malicious message falsely claimed that an entropy flaw involving STM32 microcontrollers could make Trezor recovery seeds vulnerable to brute-force reconstruction. Trezor explicitly rejected the warning as fraudulent, reinforcing its standing guidance that the company will never ask customers to enter, verify or disclose their wallet backup through a website or unsolicited communication.

Reports from affected users indicate that the phishing flow attempted to direct victims toward a page or downloaded file designed to collect recovery-seed information. Anyone who disclosed a valid wallet backup could face direct loss of funds because possession of the seed is sufficient to reconstruct control over the associated wallet. Simply receiving the email, however, does not compromise a hardware wallet.

The incident illustrates a recurring security problem for self-custody products: attackers do not necessarily need to defeat hardware protections if they can compromise communication channels and convince users to surrender credentials voluntarily. Third-party infrastructure can therefore become part of the attack surface even when private keys remain securely isolated inside the device.

ShipMonk Link Remains Unconfirmed

The latest phishing campaign follows a separate breach involving Trezor fulfillment provider ShipMonk. Trezor said that incident ultimately exposed customer information belonging to 80,689 people, including combinations of names, email addresses, phone numbers and shipping addresses. Trezor has not established that the ShipMonk data was used in the new email-provider attack, so the two incidents should be treated separately unless the company confirms a connection.

The ShipMonk breach nevertheless increases the broader phishing risk around affected customers because exposed contact information can be used to create more convincing targeted messages. Trezor previously warned that leaked customer data could support fraudulent emails, calls, letters and impersonation attempts, while stressing that its devices and internal systems were not compromised in that incident.

The operational rule remains straightforward: never enter a recovery seed in response to an email, web link or unsolicited security warning. The current incident is a compromise of communications infrastructure, not evidence of a newly confirmed vulnerability in Trezor hardware, and the company’s investigation into the third-party provider remains ongoing.

Shatoshi Pick
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.