Trezor said attackers breached its third-party email provider and sent customers a phishing email disguised as a critical chip security alert, the company’s third vendor failure in four weeks.
The hardware wallet company said it took down the domain behind the campaign and is investigating how attackers reached its legitimate domain. Reportedly, wallets, keys, and recovery backups were never exposed.
An August 10 incident at ShipMonk, the partner that ships Trezor orders, started the run. A September 4 update pushed the number of exposed customers above 80,000.
That leak held names, phone numbers, and home addresses. BeInCrypto reported in August that devices stayed safe while the phishing and scam risk climbed. Customers have since reported scam calls and printed letters.
The pattern is old. Trezor warned 66,000 users after a support portal breach in 2024, and rivals have stumbled too, with SafePal leaking nearly 40,000 records last month. The devices hold up. The partners holding customer data do not.
The email arrived as a critical security alert about an “STM32 Entropy Vulnerability.” STM32 names the family of small chips inside Trezor devices.
Entropy is the randomness a wallet uses to build a recovery phrase, the backup that controls the funds. Weak randomness would be a real danger, which makes the lure credible to a worried owner.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” the team warned.
Follow us on X to get the latest news as it happens
Leaked contact details paired with a genuine sender domain strip away the signals users lean on.
“There are convincing phishing emails going out right now from hardware wallet companies (have heard Trezor and Bitbox at least). It’s likely that a marketing email provider was compromised. That will mean more customer emails are leaked,” one user noted.
Indeed, BitBox, a Swiss-made Bitcoin hardware wallet also reported a similar incident, only that the phishing mail was sent out to their newsletter subscribers.
Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised.Multiple other Bitcoin companies got targeted as well, and it appears that we all share the…
— BitBox (@BitBoxSwiss) September 9, 2026
According to BitBox, the phishing attacks may have targeted Bitcoin companies sharing the same newsletter provider.