Trezor’s latest security incident did not begin with a compromised hardware wallet. It began with an email provider.
The hardware wallet maker said attackers breached a third-party email provider and used the access to send customers a phishing message disguised as an urgent warning about a supposed chip vulnerability. The company said wallets, private keys, and recovery backups were not exposed.
The incident is Trezor’s third vendor-related failure in four weeks, making the episode less about a single phishing campaign and more about an increasingly familiar problem: the security perimeter around crypto hardware can extend far beyond the device itself.
Trezor said it has taken down the domain used in the phishing operation and is investigating how attackers were able to reach what appeared to be a legitimate Trezor-associated domain.
For customers, the danger is psychological as much as technical. A convincing message from a familiar brand can make a malicious link feel routine.
The timing also adds another layer to the story. On August 10, Trezor disclosed an incident involving ShipMonk, the logistics company handling its orders. A September 4 update said the number of affected customers had risen above 80,000.
That earlier breach exposed names, phone numbers, and home addresses. While the devices themselves remained secure, the leaked information created new opportunities for phishing, scam calls, and even physical letters targeting customers.
The pattern is hardly unique to Trezor. The company warned around 66,000 users after a support portal breach in 2024. More recently, rival hardware wallet maker SafePal disclosed a leak involving nearly 40,000 records.
The Trezor security incident turns trust into the target
The latest Trezor security incident worked because the fake warning sounded technically plausible.
The message claimed there was an “STM32 Entropy Vulnerability.” STM32 refers to a family of microchips used inside Trezor devices, while entropy describes the randomness used to generate a wallet’s recovery phrase — the backup that ultimately controls access to its funds.
That combination of real technical language and a high-stakes security warning gives the scam an unusually convincing setup. A hardware wallet owner who sees a message suggesting that the device’s randomness may be compromised has an obvious reason to pay attention.
Trezor explicitly warned customers not to trust the email.
“Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” the team said.
The company said users should ignore unexpected Trezor emails, particularly those mentioning STM32 or entropy, and should never enter a recovery phrase or device passcode into a website.
Customers should also be cautious with unsolicited phone calls or physical mail claiming to be connected to Trezor. Official notices should be verified through trezor.io or the company’s verified account on X.
Anyone who entered a recovery backup into a page connected to the campaign should move their funds to a new wallet.
The reason this episode matters extends beyond one compromised vendor. Once customer records, email systems, and trusted communication channels become interconnected, attackers do not necessarily need to break the hardware itself. They can simply borrow the credibility surrounding it.
That concern appears to extend across the hardware wallet industry. Swiss Bitcoin hardware maker BitBox also reported a similar incident involving phishing emails sent to newsletter subscribers. According to BitBox, the attacks may have targeted Bitcoin companies using the same newsletter provider.
For users, that creates an uncomfortable contradiction. The wallet can remain technically intact while the ecosystem around it becomes the attack surface.
In one online discussion, a user warned that convincing phishing emails were circulating from hardware wallet companies, including Trezor and BitBox, and suggested that a compromised marketing email provider could expose even more customer addresses.
The practical lesson is simple, even if the threat is not: a legitimate-looking sender is no longer enough. When the message is unexpected and the requested action involves credentials, recovery phrases, or moving funds, skepticism is part of the security system.
