Trezor Reveals Third Vendor Breach in 4 Weeks After Phishing Attack

Trezor's third-party email provider was hacked, sending a phishing alert to customers.

09/09/2026 21:2610 min read

Trezor disclosed that a third-party email service was compromised, leading to a phishing email sent to customers that posed as a vital chip security alert. This marks the hardware wallet firm's third vendor-related incident in less than a month.

The company stated it has taken down the domain involved in the campaign and is investigating how attackers managed to use its legitimate domain. According to reports, no wallets, private keys, or recovery backups were compromised.

Trezor's Email Provider Breach Follows the ShipMonk Leak

The string of incidents began on August 10 with a breach at ShipMonk, the logistics partner handling Trezor shipments. A September 4 update revealed that the number of affected customers had surpassed 80,000.

That data leak exposed names, phone numbers, and home addresses. As BeInCrypto reported in August, the devices themselves remained secure, though the risk of phishing and scams increased. Customers have since reported receiving scam calls and printed letters.

This pattern is not new. Trezor alerted 66,000 users following a support portal breach in 2024, and competitors have faced similar issues, with SafePal leaking close to 40,000 records last month. While the hardware wallets remain secure, the partners holding customer data have proven vulnerable.

Why the Fake STM32 Alert Works

The phishing email was designed as a critical security warning about an "STM32 Entropy Vulnerability." STM32 refers to a family of microchips used inside Trezor devices.

Entropy is the randomness that a wallet relies on to generate a recovery phrase, which controls the funds. If the randomness were weak, it would pose a genuine threat, making the lure appear credible to concerned users.

Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” the team warned.

What Trezor Users Should Do Now

  • Avoid clicking on links in any unexpected email from Trezor, particularly those mentioning STM32 or entropy.
  • Never enter a recovery phrase or device passcode into a website.
  • Treat unsolicited phone calls and physical letters as suspicious until verified.
  • Consult trezor.io or the verified Trezor account on X for legitimate updates.
  • Anyone who entered a backup on a linked page should transfer funds to a new wallet.

Combined with leaked contact details and a genuine sender domain, the attack removes the usual warning signs users depend on.

There are convincing phishing emails going out right now from hardware wallet companies (have heard Trezor and Bitbox at least). It's likely that a marketing email provider was compromised. That will mean more customer emails are leaked.

Stay frosty and don't trust provider… pic.twitter.com/jHtdRE9S2A

— Nick Neuman (@Nneuman) September 9, 2026

The coming days will depend on whether Trezor names the provider involved and how many email addresses were exposed.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles