Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Trezor Warns of Phishing Attack After Email Provider Breach

Published 10 September 2026

Hardware wallet manufacturer Trezor has alerted its users to a phishing campaign that utilized its legitimate domain after a breach of its third-party email provider. The fraudulent emails, sent on Wednesday, September 9, 2026, were titled "Critical Security Alert STM32 Entropy Vulnerability." Trezor stated that these messages were not from the company and warned users not to click on any links within them. The attackers reportedly exploited the compromised provider to send the emails, which falsely claimed a hardware vulnerability in STM32 microcontrollers could weaken the randomness of device recovery phrases. This specific vulnerability claim was designed to exploit user fears, particularly following recent incidents involving hardware wallet security. Trezor has since taken down the domain used in the attack and is actively investigating how the attackers gained access to its official domain for the phishing emails. The company has also confirmed that no user funds, wallets, keys, or recovery backups were exposed in this incident. This latest security alert follows a significant data breach at Trezor's shipping partner, ShipMonk, which was disclosed last month.

0:00 / 0:00