Physical wallet producer Trezor reported that its external email vendor suffered a security compromise, allowing fraudulent messages to go out through its authorized web domain.
“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” Trezor stated in a Wednesday post on X.
Trezor noted that it has since disabled the domain and continues to look into the matter, including how attackers managed to leverage its legitimate domain for the scam messages.
On that same day, Swiss bitcoin (BTC) hardware wallet manufacturer BitBox shared that a comparable deceptive email was making the rounds impersonating them.
Marcello Paz, a digital asset analyst known on X as “MHPaz,” mentioned he got the fraudulent message and posted images revealing it urged users to update their physical devices because of a “critical” flaw allegedly impacting newer hardware. Unlike standard scam messages that rely on lookalike domains, these emails displayed authentic domain names and digital signatures.
Not the first
Just last month, Trezor revealed a significant security event wherein a breach at ShipMonk, its logistics vendor, leaked personal details of nearly 14,000 buyers. Although Trezor initially stated roughly 13,700 users had their names, municipalities, and email addresses compromised, the firm announced earlier this month that an additional 67,000 U.S. buyers were impacted by that exact breach.
During June, the Donjon security research division at Ledger revealed a hardware weakness within the TROPIC01 chip utilized inside the Trezor Safe 7, showcasing a laboratory laser attack that bypassed the chip’s firmware check mechanisms. Trezor maintained at the time that user funds faced zero threat.
A 2020 Ledger security incident leaked records belonging to more than 270,000 users, with names, email addresses, phone contacts, and occasionally home addresses subsequently leaked on a cybercrime forum. Ledger clientele have kept reporting getting fraudulent phone calls and physical mail years later.
Originally published at https://www.theblock.co/news/defi/2026-09-09-trezor-phishing-emails-414086.