Crypto News

Trezor Says Third-Party Breach Led to Phishing Emails From Official Domain

Trezor Says Third-Party Breach Led to Phishing Emails From Official Domain

Trezor Warns Users of Phishing Emails From Official Domain

On September 9, 2026, Trezor, a hardware wallet maker, alerted users to phishing emails sent from its official domain after a breach at its third-party email provider. The emails falsely claim a critical security vulnerability in Trezor devices and ask users to update their wallets.

Trezor stated it has taken down the affected domain and is investigating how hackers used its legitimate domain for the phishing attempt.

Key Details From the Incident

  • The phishing email is titled "Critical Security Alert: STM32 Entropy Vulnerability."
  • Emails appeared from Trezor's official domain, making them seem legitimate.
  • BitBox, another hardware wallet company, reported similar phishing emails circulating under its name.
  • A crypto commentator shared screenshots showing the email uses official signatures, unlike typical phishing with fake addresses.

What Trezor Officially Stated

In an X post, Trezor wrote: "Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link." The company confirmed the breach of its email provider and advised caution.

Reports From Other Observers

BitBox reported phishing emails disguised under its brand. Commentator MHPaz shared screenshots of the Trezor phishing email, noting it uses official domain names and signatures, differing from usual phishing emails.

What Is Confirmed

It is confirmed that phishing emails were sent from Trezor's official domain due to a third-party email provider breach. The emails falsely claim a security vulnerability. No reports of funds lost from this specific phishing campaign are mentioned in the sources.

What Remains Unclear

The exact method of the third-party email provider breach and how hackers used Trezor's domain are under investigation. The full number of users affected is not specified.

Why This Matters for Crypto Users

Hardware wallets are designed to secure cryptocurrency offline. Phishing from an official domain can trick users into revealing sensitive information, risking fund loss. Previous incidents mentioned in the source, such as the ShipMonk breach and Ledger's 2020 breach, show that data exposures can lead to ongoing scams, highlighting the need for vigilance.

Next Steps From Trezor

Trezor is investigating the breach and has disabled the affected domain. No further actions or timelines are provided in the sources.

Sources

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!