Trezor has warned its users about a phishing campaign after the company’s third-party email provider was breached. On September 9, 2026, users began receiving a fake security email titled “Critical Security Alert: STM32 Entropy Vulnerability.” Trezor confirmed that the message was not sent by the company and told users not to click any links inside it. The company also said it had taken down the affected domain and started investigating how attackers gained access to its legitimate email infrastructure.
The attack is particularly concerning because the phishing email looked much more genuine than a normal scam message. Reports from recipients showed that the email appeared to come from Trezor’s legitimate mailing infrastructure rather than an obvious fake address. Independent analysis also found that the message passed common email security checks including SPF, DKIM and DMARC. This made the message appear authentic to email systems and increased the chances that users would trust the warning and follow its instructions.
The fraudulent email claimed that a serious problem involving the STM32 chip could affect the security of Trezor wallets. It told recipients to check whether their device was affected and directed them toward a verification process. However, the claimed vulnerability was not a real Trezor security issue, and the message was designed to trick users into providing sensitive wallet information. Reports from users showed that the malicious page could ask for information connected to their wallet, making the campaign a serious threat to cryptocurrency holders.
Security researchers and affected users quickly noticed that the campaign was unusually convincing because the attackers appeared to use Trezor’s real email-sending infrastructure. Some recipients reported that the message arrived from addresses and domains associated with Trezor, while technical checks showed valid authentication results. This does not mean the email was legitimate; instead, it indicates that the attackers gained unauthorized access through the third-party email provider used by Trezor. Trezor has confirmed the provider breach and said it is investigating how the attackers obtained access.
Trezor has strongly reminded users that their recovery seed or wallet backup must never be entered into a website or shared with anyone. The company says legitimate Trezor communications will never ask users to provide their wallet backup, PIN, passwords or similar sensitive information. Users are also advised to avoid clicking links in suspicious messages and to verify security information through official Trezor channels. The warning is especially important because phishing attacks can be used to steal wallet information and ultimately give attackers control over cryptocurrency funds.
The latest incident comes after Trezor customers were already warned about phishing risks following a separate August 2026 data breach at shipping provider ShipMonk, which exposed customer information and increased the risk of targeted scams. Trezor has said that its own systems and hardware devices were not compromised in that earlier incident, but exposed customer details could be used for convincing phishing emails, calls or letters. With the latest email-provider breach now confirmed, users should treat unexpected Trezor security messages with extreme caution and never provide their recovery phrase or other wallet secrets.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news