Trezor Issues Security Warning After Third-Party Security Breach
The breach comes soon after a security incident at ShipMonk compromised the personal information of Trezor users.
Trezor Warns Of Third-Party BreachTrezor issued a warning in an official X post, informing users that the email“Critical Security Alert: STM32 Entropy Vulnerability” was a phishing attempt and urged them to avoid clicking any links.
“Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link.”
The compromised domain has since been taken down, and Trezor has launched a full investigation into the breach and how hackers used the company's official domain to send phishing emails. Marcello Paz, a crypto commentator, said he received the phishing email in question and shared screenshots asking customers to update their hardware wallets due to a“critical vulnerability.” Unlike typical phishing emails, the email's credentials showed official domain names and signatures.
“Hello @trezor, I received a“Critical Security Alert: STM32 Entropy Vulnerability” email today (9 Sep 2026). Gmail shows From: Trezor Security <...>, Return-Path:..., Sendinblue campaign, DKIM/SPF/DMARC pass for trezor. Body claims a factory STM32 RNG defect (~1 in 4 devices), ~40-bit seeds, and a“check if you're affected” link via trezor plus xPub verification. This matches the entropy-phishing wave, not any official advisory.”
Similar Attempt On BitBoxBitBox, a Swiss Bitcoin hardware wallet maker, reported a similar phishing attempt. The company shared a similar email on its official X account, warning users it was a phishing attempt and urged them to be cautious.
“There is currently a phishing email going around that's pretending to come from us. Please do not follow the instructions in the email! We are currently investigating.”
Previous Security IncidentsLast month, Trezor's shipping provider ShipMonk was hit by a major security breach that exposed personal information linked to its customers. Trezor initially disclosed that personal information, including names, cities, and email addresses of 13,700 users, was compromised. However, it said another 67,000 US-based users were affected by the breach.
Hardware wallets have been hit by several security vulnerabilities and breaches recently. Ledger 's security team disclosed a major vulnerability in Trezor Safe 7's TROPIC01 chip, demonstrating how a lab-based laser attack bypassed its firmware verification system. Ledger suffered a major security breach in 2020 that exposed the personal information of over 270,000 customers, including names, email addresses, phone numbers, and even home addresses. The details were published on a dark web forum, with impacted customers receiving scam calls and physical letters even years later.
Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.
Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment