- Trezor confirmed on September 9 that its third-party email provider was breached, letting attackers send phishing emails from Trezor’s real domain.
- The fake email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” urged recipients to click a link.
- BitBox reported a near-identical phishing campaign the same day; Trezor has since taken down the compromised domain and is investigating.
Trezor disclosed on X on Wednesday, September 9, that its email provider, a third-party vendor rather than Trezor’s own infrastructure, had been compromised. That let attackers send phishing emails that appeared to come from Trezor’s legitimate domain, making them far harder to spot than a typical spoofed sender address.
The bait was a fake warning titled “Critical Security Alert: STM32 Entropy Vulnerability,” referencing the microcontroller chip used in Trezor’s hardware wallets, a choice of subject line designed to sound exactly like the kind of alert a security-conscious user would feel obligated to click.
“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”
BitBox, a competing hardware wallet maker, reported a nearly identical phishing wave hitting its own customers on the same day, suggesting either a coordinated campaign against the hardware wallet sector broadly or attackers reusing a successful template across multiple targets once it worked once.
This isn’t Trezor’s first brush with a third-party breach this year. In August, a compromise at its shipping provider, ShipMonk, exposed personal information for roughly 13,700 customers before expanding to cover 67,000 more US customers. Two breaches at two different vendors within a month of each other point to the same underlying problem: a hardware wallet can be cryptographically secure while the company’s ordinary business vendors, shipping and email among them, remain a much softer target.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.












