Hardware wallet manufacturer Trezor has issued a warning to its user base after a phishing email disguised as an official product advisory circulated through what the company describes as a compromised third-party mail service.
The message, which surfaced late on September 9, carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and appeared to arrive from a legitimate Trezor address, according to recipients and Trezor’s own alert. Trezor said the message was a phishing attempt and told users not to click any link.
The company has not, in the cited X post, stated that devices, private keys, or recovery backups were examined or confirmed untouched in this specific incident.
Trezor Confirms the Alert is Phishing
At 20:37 Coordinated Universal Time (UTC) on September 9, 2026, Trezor posted on X that its third-party email provider had been breached and that the STM32 entropy alert was a phishing attempt.
The company urged recipients not to click any link in the message and said it had taken down the domain used in the campaign while investigating how attackers gained access to its legitimate mail infrastructure. In a follow-up reply at 22:20 UTC, Trezor reiterated that the email provider had been compromised.
How the Fake Email Was Constructed
Recipients who posted message headers said the phishing email displayed the sender name as “Trezor Security” and used help@trezor.io in the From field, with a Return-Path pointing to mailing.trezor.io.
Because the message travelled through Trezor’s own newsletter infrastructure rather than a lookalike domain, Gmail treated it as authenticated, allowing it to pass standard inbox checks such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC).
Security researcher YFarmX, which reviewed the DNS records and message headers on September 9, reported that the body of the email claimed a factory defect in the STM32 microcontroller, a low-power chip used across a range of hardware wallets, alleged that roughly one in four devices produced weak 40-bit seeds, and directed recipients to a “check if you’re affected” page hosted on r.mailing.trezor.io, a click-tracking subdomain within Trezor’s own mailing infrastructure.
Some variants of the phishing page reportedly asked users to verify their xPub, or extended public key. An xPub cannot itself authorize outgoing transactions, but it can expose every address and balance associated with a wallet, effectively unmasking a holder’s on-chain activity.
Trezor has not published any product advisory matching the STM32 claim. The lure borrowed language from a real class of hardware wallet risk, which likely contributed to its effectiveness. A separate and verified randomness flaw affecting certain Coldcard firmware versions was documented previously by The Crypto Times and is unrelated to this campaign.
Shared Newsletter Provider Draws in Multiple Firms
The incident does not appear isolated to Trezor. Swiss hardware wallet manufacturer BitBox issued its own warning at 20:01 UTC on September 9, followed by a fuller assessment at 21:03 UTC.
BitBox said a preliminary review indicated that its newsletter provider had “very likely” been compromised, and that several Bitcoin companies appeared to share the same platform. The firm said it had contacted the provider, reported phishing domains, and emailed a direct warning to newsletter subscribers, adding that most phishing links appeared to have been taken offline while the investigation continued.
German-language Bitcoin publication Blocktrainer, in an article timestamped 22:51 on September 9 on its site (Central European Summer Time, 20:51 UTC), said the wave targeted Trezor, BitBox, and portfolio tracker CoinTracking, and that unauthorized Application Programming Interface (API) keys had been created inside affected accounts on Brevo, a European email marketing platform previously known as Sendinblue. Blocktrainer, which also uses Brevo, said an initial check of its own list did not surface a matching send.
YFarmX separately documented a shared DKIM signing key across trezor.io, bitbox.swiss, and shiftcrypto.ch, a technical marker consistent with a common mailing vendor. Trezor has not publicly named the vendor in its own statements, so the shared-provider identification rests on third-party analysis rather than an official disclosure.
Casa co-founder Nick Neuman and Casa chief security officer (CSO) Jameson Lopp both posted on X that the messages did not resemble ordinary spoofing and that none of the affected companies had published a matching security advisory.
Takedown Status and Residual Risk
Trezor said it had removed the domain used in the campaign. YFarmX checked DNS records at 21:18 UTC and again at 22:26 UTC on September 9, and reported that the SPF record for mailing.trezor.io had been withdrawn, blocking further authenticated sends from that host.
The tracking hostname still resolved but failed HyperText Transfer Protocol Secure (HTTPS) checks, meaning residual links in circulating copies of the email should error in the browser rather than load the phishing page.
That amounts to a partial takedown, not confirmation that every copy of the message is inert. As of early September 10 UTC, Trezor has not published a long-form blog note on the email incident, and its live statement remains the X thread.
A Separate Track From the ShipMonk Shipping Data Leak
The September 9 email campaign is a mail-delivery compromise. It is distinct from the ShipMonk fulfillment breach that Trezor first disclosed on August 13 and expanded on September 4.
That earlier shipping-provider incident exposed data belonging to an initial 11,742 customers with full records and 1,947 with partial records (13,689 combined) and, in a subsequent disclosure, approximately 67,000 additional United States (US) customers drawn from 2019 to 2021 records that Trezor said should have been deleted, taking combined public totals to about 80,700 people.
Names, email addresses, phone numbers, and shipping addresses were exposed, while wallet seeds were not. The company set out its own account of that incident on its official blog.
Those leaks raise the probability that phishing attempts against Trezor customers will look increasingly personalized in the weeks ahead. On the public record so far, there is no evidence that the ShipMonk data was the mailing list used for the September 9 blast.
Both Trezor and BitBox have described the newer messages as originating from newsletter accounts rather than fulfilment records. A Google-indexed phishing site tied to Trezor spoofing had already claimed around 80 victims, according to earlier Crypto Times reporting.
What is Settled and What Remains Open
Several points are now on the public record. The STM32 entropy email is not a Trezor product advisory. Trezor and BitBox have both stated that a third-party newsletter provider was abused. Authenticated mail can still be malicious if the sending account is taken over. Trezor and BitBox have framed the incident as a mail-provider compromise, not a compromise of wallet hardware. Neither company cited posts for September 9 inventory devices or recovery backups as audited in this event.
Other questions remain unresolved. It is not yet clear whether Brevo’s core platform was breached or whether only customer-level API keys were abused. The exact number of recipients has not been disclosed. Whether any user entered a seed phrase or xPub on a linked page is unknown. How attackers first obtained access to the affected sending accounts is still under investigation.
Trezor’s standing guidance is unchanged. Wallet backups should never be typed into a website, and unsolicited security emails should be treated as hostile even when the sender line and the browser padlock appear correct. Official product updates are published on the company’s verified channels and not through unexpected inbox alerts.
Also Read: HTX Faces Unverified Data Breach Claim Over 6.5M User Records
