Trezor said attackers exploited a third-party email provider on Sept. 9 to send phishing emails that looked like legitimate company security notices. The wallet maker said its devices and wallets were not affected, but warned users not to click links in the messages while it investigates how its email system was abused.

The fraudulent emails carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and falsely claimed a flaw could weaken users’ recovery phrases. The incident underscores a broader risk for hardware wallet brands: even when devices remain secure, attackers may still reach customers through trusted service providers and realistic-looking communications.

Emails appeared to come from genuine Trezor channels

The campaign stood out because the messages appeared to pass through real Trezor infrastructure rather than an obvious spoofed domain. One recipient said the email came from help@trezor.io, used a Sendinblue campaign path, and passed DKIM, SPF, and DMARC checks that are normally used to verify email authenticity.

The text of the phishing message claimed that one in four devices could be compromised and that recovery phrases might lack sufficient randomness or entropy. That framing closely resembled issues discussed in a recent attack involving Coldcard, which may have made the warning seem more credible to recipients.

Trezor says hardware was not breached

According to Trezor, the incident involved its external email provider rather than a compromise of the wallets themselves. The company said wallet operations and devices remained unaffected, and its immediate guidance was for users to avoid clicking any links contained in the alert emails.

The distinction matters because the event was presented as a security warning about device integrity, even though the known issue was a phishing campaign delivered through a communications channel. In practice, the attack targeted user trust rather than the hardware.

Reports suggest the issue may not be isolated

Nick Neuman, co-founder and CEO of Casa, said there appears to be a similar pattern among some BitBox users and suggested that a shared marketing email provider may have been breached. That claim points to the possibility that the same type of compromise could affect multiple wallet brands if they rely on common external vendors.

If that is the case, the problem extends beyond any single manufacturer. Wallet companies may harden their products, but their brands can still be impersonated or misused through systems they do not fully control, including email platforms and other third-party services.

Leaked customer context can fuel more convincing scams

The article draws a line between device exploits and customer-data incidents. A previous Cryptopolitan report said phishing attempts against Ledger users also reached people through physical mail, while SafePal disclosed in 2026 that an authorization error in an order-tracking plugin exposed data tied to about 39,798 customers. SafePal said seed phrases, private keys, and wallet credentials were not compromised.

Even without direct access to wallet secrets, contact and purchase data can be highly valuable to scammers. Chainalysis estimated that scams and fraud stole $17 billion in 2025, while impersonation scams rose more than 1,400% year over year. It also said scams with on-chain links to AI vendors brought in 4.5 times more revenue per operation than those without such links.

A shipping or order record can give criminals a name, email, phone number, address, and confirmation that someone uses a crypto security product. That information can then be used to craft persuasive emails, calls, letters, or other approaches that appear tailored and legitimate.

Next step is the investigation into provider access

For now, the confirmed facts are limited: Trezor says the phishing emails were sent through a compromised third-party provider, the messages falsely warned of an STM32-related entropy issue, and the company says its wallets were not affected. Trezor has blocked the sending domain and is investigating how the attackers were able to use its email setup.

The broader takeaway is not that a hardware wallet was broken, but that the security boundary now includes the outside systems surrounding the device. The next confirmed step is Trezor’s investigation into the provider compromise and whether any wider third-party exposure is involved.

Source: Cryptopolitan