Hackers breached Trezor's email and used it to send phishing

iEXExchanger
Hackers breached Trezor's email and used it to send phishing

Hackers broke into a third-party email provider used by Trezor and sent phishing from the company's real address, claiming a fake chip flaw. Devices were untouched, but customer data had leaked a month earlier.

The wallet itself was never touched. What got compromised was Trezor's email system — and that was enough to send phishing messages from a completely legitimate company address. On September 9, hardware wallet owners started receiving a message titled "Critical Security Alert: STM32 Entropy Vulnerability," claiming a chip flaw had weakened seed-phrase protection. The email came from help@trezor.io and passed SPF, DKIM, and DMARC checks, so most spam filters waved it straight through.

There was no such vulnerability. Trezor confirmed attackers had broken into a third-party email provider and used it to blast out the fake alert. "This email is not from us, and it's a phishing attempt. Do not click any links," the company said, shutting down the compromised sending channel and opening an investigation.

The link pointed to a fake site styled to look exactly like Trezor's interface, asking visitors to type in their recovery seed or password — precisely what a hardware wallet exists to keep away from any screen. Swiss rival BitBox reported nearly identical emails landing the same day, suggesting both companies rely on the same breached email vendor.

This isn't an isolated slip. A month earlier, Trezor's shipping partner ShipMonk was hacked, leaking contact details for roughly 80,000 customers — names, cities, and email addresses tied to orders placed between 2019 and 2021. That leaked list looks like exactly what made this phishing wave so convincing: attackers already had real customer emails to target.

The device itself was never at risk, and Trezor says no confirmed thefts have been tied to the campaign so far. Still, the episode is a reminder that for cold-wallet owners, the weakest link keeps turning out to be an inbox, not a chip.

Questions and answers

Frequently asked questions about this article

What happened to Trezor?

On September 9, 2026, hackers breached a third-party email provider used by Trezor and sent a phishing email in the company's name about a fake STM32 chip vulnerability, trying to trick users into revealing their seed phrases.

Was the Trezor device itself hacked?

No. Only a third-party email service was compromised. Trezor's hardware wallets and firmware were not affected, and the STM32 chip flaw described in the phishing email does not exist.

What should Trezor owners do now?

Ignore the 'STM32 Entropy Vulnerability' email, avoid clicking any links in it, and never type a seed phrase into any website — Trezor never asks for it. Firmware updates should only be checked through the official Trezor Suite app.

How is this related to the ShipMonk breach?

A month earlier, Trezor's shipping partner ShipMonk was hacked, leaking names, cities, and emails of roughly 80,000 customers tied to orders from 2019-2021. That leaked data likely helped attackers make this phishing wave more targeted and convincing.