Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Trezor Confirms Phishing Attack After Email Provider Breach, Users Warned

The phishing email exploited Trezor’s legitimate mailing infrastructure, passing SPF, DKIM and DMARC checks while directing users to a fake STM32 vulnerability page.

Written By Dishita Malvania
Published 1 minute ago
Make The Crypto Times preferred on GoogleGoogle
Trezor Confirms Phishing Attack After Email Provider Breach, Users Warned

Hardware wallet manufacturer Trezor has issued a warning to its user base after a phishing email disguised as an official product advisory circulated through what the company describes as a compromised third-party mail service.

The message, which surfaced late on September 9, carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and appeared to arrive from a legitimate Trezor address, according to recipients and Trezor’s own alert. Trezor said the message was a phishing attempt and told users not to click any link. 

The company has not, in the cited X post, stated that devices, private keys, or recovery backups were examined or confirmed untouched in this specific incident.

AI Summary
Show
Phishing campaign could expose users’ xPub data, risking market‑wide privacy breaches and potential asset tracing.
Over 80,000 Trezor customers previously affected by data leak, increasing phishing success odds and investor confidence concerns.
Shared newsletter provider breach links Trezor and BitBox, prompting market scrutiny of third‑party email services used by crypto firms.

Trezor Confirms the Alert is Phishing

At 20:37 Coordinated Universal Time (UTC) on September 9, 2026, Trezor posted on X that its third-party email provider had been breached and that the STM32 entropy alert was a phishing attempt. 

Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.

We have taken down the domain, and we are investigating…

— Trezor (@Trezor) September 9, 2026

The company urged recipients not to click any link in the message and said it had taken down the domain used in the campaign while investigating how attackers gained access to its legitimate mail infrastructure. In a follow-up reply at 22:20 UTC, Trezor reiterated that the email provider had been compromised. 

How the Fake Email Was Constructed

Recipients who posted message headers said the phishing email displayed the sender name as “Trezor Security” and used help@trezor.io in the From field, with a Return-Path pointing to mailing.trezor.io. 

Because the message travelled through Trezor’s own newsletter infrastructure rather than a lookalike domain, Gmail treated it as authenticated, allowing it to pass standard inbox checks such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC).

Security researcher YFarmX, which reviewed the DNS records and message headers on September 9, reported that the body of the email claimed a factory defect in the STM32 microcontroller, a low-power chip used across a range of hardware wallets, alleged that roughly one in four devices produced weak 40-bit seeds, and directed recipients to a “check if you’re affected” page hosted on r.mailing.trezor.io, a click-tracking subdomain within Trezor’s own mailing infrastructure.

Some variants of the phishing page reportedly asked users to verify their xPub, or extended public key. An xPub cannot itself authorize outgoing transactions, but it can expose every address and balance associated with a wallet, effectively unmasking a holder’s on-chain activity.

Trezor has not published any product advisory matching the STM32 claim. The lure borrowed language from a real class of hardware wallet risk, which likely contributed to its effectiveness. A separate and verified randomness flaw affecting certain Coldcard firmware versions was documented previously by The Crypto Times and is unrelated to this campaign.

Shared Newsletter Provider Draws in Multiple Firms

The incident does not appear isolated to Trezor. Swiss hardware wallet manufacturer BitBox issued its own warning at 20:01 UTC on September 9, followed by a fuller assessment at 21:03 UTC.

BitBox said a preliminary review indicated that its newsletter provider had “very likely” been compromised, and that several Bitcoin companies appeared to share the same platform. The firm said it had contacted the provider, reported phishing domains, and emailed a direct warning to newsletter subscribers, adding that most phishing links appeared to have been taken offline while the investigation continued.

German-language Bitcoin publication Blocktrainer, in an article timestamped 22:51 on September 9 on its site (Central European Summer Time, 20:51 UTC), said the wave targeted Trezor, BitBox, and portfolio tracker CoinTracking, and that unauthorized Application Programming Interface (API) keys had been created inside affected accounts on Brevo, a European email marketing platform previously known as Sendinblue. Blocktrainer, which also uses Brevo, said an initial check of its own list did not surface a matching send.

YFarmX separately documented a shared DKIM signing key across trezor.io, bitbox.swiss, and shiftcrypto.ch, a technical marker consistent with a common mailing vendor. Trezor has not publicly named the vendor in its own statements, so the shared-provider identification rests on third-party analysis rather than an official disclosure.

There are convincing phishing emails going out right now from hardware wallet companies (have heard Trezor and Bitbox at least). It's likely that a marketing email provider was compromised. That will mean more customer emails are leaked.

Stay frosty and don't trust provider… pic.twitter.com/jHtdRE9S2A

— Nick Neuman (@Nneuman) September 9, 2026

Casa co-founder Nick Neuman and Casa chief security officer (CSO) Jameson Lopp both posted on X that the messages did not resemble ordinary spoofing and that none of the affected companies had published a matching security advisory.

Takedown Status and Residual Risk

Trezor said it had removed the domain used in the campaign. YFarmX checked DNS records at 21:18 UTC and again at 22:26 UTC on September 9, and reported that the SPF record for mailing.trezor.io had been withdrawn, blocking further authenticated sends from that host. 

The tracking hostname still resolved but failed HyperText Transfer Protocol Secure (HTTPS) checks, meaning residual links in circulating copies of the email should error in the browser rather than load the phishing page.

That amounts to a partial takedown, not confirmation that every copy of the message is inert. As of early September 10 UTC, Trezor has not published a long-form blog note on the email incident, and its live statement remains the X thread.

A Separate Track From the ShipMonk Shipping Data Leak

The September 9 email campaign is a mail-delivery compromise. It is distinct from the ShipMonk fulfillment breach that Trezor first disclosed on August 13 and expanded on September 4.

That earlier shipping-provider incident exposed data belonging to an initial 11,742 customers with full records and 1,947 with partial records (13,689 combined) and, in a subsequent disclosure, approximately 67,000 additional United States (US) customers drawn from 2019 to 2021 records that Trezor said should have been deleted, taking combined public totals to about 80,700 people. 

Names, email addresses, phone numbers, and shipping addresses were exposed, while wallet seeds were not. The company set out its own account of that incident on its official blog.

Those leaks raise the probability that phishing attempts against Trezor customers will look increasingly personalized in the weeks ahead. On the public record so far, there is no evidence that the ShipMonk data was the mailing list used for the September 9 blast. 

Both Trezor and BitBox have described the newer messages as originating from newsletter accounts rather than fulfilment records. A Google-indexed phishing site tied to Trezor spoofing had already claimed around 80 victims, according to earlier Crypto Times reporting.

What is Settled and What Remains Open

Several points are now on the public record. The STM32 entropy email is not a Trezor product advisory. Trezor and BitBox have both stated that a third-party newsletter provider was abused. Authenticated mail can still be malicious if the sending account is taken over. Trezor and BitBox have framed the incident as a mail-provider compromise, not a compromise of wallet hardware. Neither company cited posts for September 9 inventory devices or recovery backups as audited in this event.

Other questions remain unresolved. It is not yet clear whether Brevo’s core platform was breached or whether only customer-level API keys were abused. The exact number of recipients has not been disclosed. Whether any user entered a seed phrase or xPub on a linked page is unknown. How attackers first obtained access to the affected sending accounts is still under investigation.

Trezor’s standing guidance is unchanged. Wallet backups should never be typed into a website, and unsolicited security emails should be treated as hostile even when the sender line and the browser padlock appear correct. Official product updates are published on the company’s verified channels and not through unexpected inbox alerts.

Also Read: HTX Faces Unverified Data Breach Claim Over 6.5M User Records

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Hunter Biden Denies $LAPTOP Profit as Memecoin Crashes 95%, Foundation's X Account Suspended
Hunter Biden Denies $LAPTOP Profit as Memecoin Crashes 95%, Foundation’s X Account Suspended
Bitcoin Kidnapping Plot Lands Man 15-Year Prison Sentence
Bitcoin Kidnapping Plot Lands Man 15-Year Prison Sentence
HTX Faces Unverified Data Breach Claim Over 6.5M User Records
HTX Faces Unverified Data Breach Claim Over 6.5M User Records
Robinhood CEO Defends Stock Tokens After AMC Criticism 
Robinhood CEO Defends Stock Tokens After AMC Criticism 
Portrait of U.S. Treasury Assistant Secretary Paul Rosen wearing glasses and a suit
Treasury Chief Calls for Progress on Digital Asset Bill

Find Us on Socials

You may also like

RBI Deputy Governor T. Rabi Sankar speaking at a CAFRAL financial event.

RBI Official Warns on Legal, Privacy Risks in Tokenization

Illuminated LayerZero logo on a dark wall.

LayerZero Unveils Akita for Post-Quantum ZK Security

Smartphone displaying the MetaMask logo next to a enlarged close-up of the orange fox icon.

Consensys Splits Into Two Companies as MetaMask Goes Independent 

U.S. Bank and Stellar logos displayed side-by-side on a blue and purple gradient background.

U.S. Bank Launches Its Own USBDC Stablecoin on the StellarOrg Network

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information