Trezor Says Third-Party Breach Led to Phishing Emails From Official Domain
Trezor Warns Users of Phishing Emails From Official Domain
On September 9, 2026, Trezor, a hardware wallet maker, alerted users to phishing emails sent from its official domain after a breach at its third-party email provider. The emails falsely claim a critical security vulnerability in Trezor devices and ask users to update their wallets.
Trezor stated it has taken down the affected domain and is investigating how hackers used its legitimate domain for the phishing attempt.
Key Details From the Incident
- The phishing email is titled "Critical Security Alert: STM32 Entropy Vulnerability."
- Emails appeared from Trezor's official domain, making them seem legitimate.
- BitBox, another hardware wallet company, reported similar phishing emails circulating under its name.
- A crypto commentator shared screenshots showing the email uses official signatures, unlike typical phishing with fake addresses.
What Trezor Officially Stated
In an X post, Trezor wrote: "Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link." The company confirmed the breach of its email provider and advised caution.
Reports From Other Observers
BitBox reported phishing emails disguised under its brand. Commentator MHPaz shared screenshots of the Trezor phishing email, noting it uses official domain names and signatures, differing from usual phishing emails.
What Is Confirmed
It is confirmed that phishing emails were sent from Trezor's official domain due to a third-party email provider breach. The emails falsely claim a security vulnerability. No reports of funds lost from this specific phishing campaign are mentioned in the sources.
What Remains Unclear
The exact method of the third-party email provider breach and how hackers used Trezor's domain are under investigation. The full number of users affected is not specified.
Why This Matters for Crypto Users
Hardware wallets are designed to secure cryptocurrency offline. Phishing from an official domain can trick users into revealing sensitive information, risking fund loss. Previous incidents mentioned in the source, such as the ShipMonk breach and Ledger's 2020 breach, show that data exposures can lead to ongoing scams, highlighting the need for vigilance.
Next Steps From Trezor
Trezor is investigating the breach and has disabled the affected domain. No further actions or timelines are provided in the sources.