Trezor has warned customers that a breach involving a third-party email provider allowed phishing messages to be distributed from the hardware wallet maker’s official email domain, creating a more convincing route for scammers to reach users.
The fraudulent emails carried the subject line, “Critical Security Alert: STM32 Entropy Vulnerability,” Trezor said in a public warning issued Wednesday. Recipients were told to update their hardware wallets to address a supposed flaw affecting newer devices. Trezor urged users not to click links in the messages.
The company said it had taken down the affected sending domain and opened an investigation into how the attackers were able to send the campaign using an official address. A phishing email sent through a legitimate company domain can evade the usual warning signs: recipients may see recognized branding, a familiar sender address, and links that appear credible at first glance.
Screenshots posted by Marcello Paz, an X user known as “MHPaz,” showed an email directing recipients to install an update for their device. The message used Trezor-style signatures and web addresses resembling official company infrastructure, illustrating how the campaign was designed to exploit trust in the sender rather than rely solely on misspelled domains or poor formatting.
BitBox reports a similar branded phishing attempt
BitBox, a Swiss Bitcoin hardware wallet manufacturer, reported a separate phishing message circulating under its branding on the same day. The company published its own alert, though the available information does not establish whether the campaigns targeting BitBox and Trezor came from the same group or used the same email infrastructure.
The overlap shows how hardware wallet brands remain valuable targets for phishing operators. Their customers are more likely than typical email users to hold private keys or recovery phrases, the sensitive credentials that can authorize transfers from self-custodied wallets. A fraudulent “security update” message can therefore be aimed at getting a user to install malicious software, disclose a recovery phrase, or connect a wallet to a fake website.
Trezor’s warning focused on links contained in the email rather than a confirmed flaw in its devices. Users who receive unexpected wallet-security alerts can verify them by opening the manufacturer’s website manually in a new browser window, rather than following a link delivered by email. Official support channels and device interfaces are safer places to check whether a firmware update is actually available.
Recent customer-data exposure raises the stakes
The phishing incident follows a separate customer-data breach involving ShipMonk, a logistics provider used by Trezor. Trezor disclosed last month that the incident initially affected about 13,700 customers whose names, cities, and email addresses were exposed. The company later said the same breach also affected another 67,000 customers in the United States.
Leaked contact data does not provide access to a hardware wallet by itself. It can make impersonation campaigns more effective, especially when attackers can match an email address with evidence that the recipient bought a particular device. A message referring to a product order, firmware update, shipping issue, or account-security warning may appear more believable when it reaches a known customer.
The two incidents involve different parts of the company’s external infrastructure: ShipMonk handled logistics data, while the latest campaign was tied to an email service provider. Together, they place attention on the vendors that sit between a hardware-wallet maker and its users. Delivery companies, marketing platforms, email providers, and customer-support services may hold contact records or have access to communication channels without controlling the wallet’s underlying security architecture.
That exposure can leave customers dealing with recurring fraud attempts long after a breach is disclosed. Ledger’s 2020 customer-data breach remains a prominent example. Information linked to more than 270,000 Ledger customers, including names, email addresses, phone numbers and, in some cases, home addresses, was later published on a hacking forum. Ledger customers subsequently reported scam calls and physical letters alongside phishing emails.
For hardware wallet users, those cases reinforce a basic operational rule: a recovery phrase should never be entered into a website, shared with support staff, or provided in response to an email alert. Legitimate wallet providers do not need a customer’s recovery phrase to deliver firmware, troubleshoot a device, or verify an account.
Hardware research has also put Trezor devices under scrutiny
The phishing emails referenced an alleged STM32 entropy vulnerability, a technical claim that can sound plausible to users aware of past research into hardware-wallet security. In June, Ledger’s Donjon security research team published findings on a laboratory laser attack against the TROPIC01 chip used in Trezor Safe 7 devices.
Ledger’s researchers said the attack bypassed the chip’s firmware-verification system under laboratory conditions. Trezor responded that user funds were not at risk. The research concerned a physical attack scenario, rather than an email-driven compromise, but phishing operators often borrow real technical language to make fabricated warnings appear urgent.
The distinction matters for users assessing a security message. A genuine device-security disclosure is normally published through a manufacturer’s official advisory pages, firmware-release notes, and verified social accounts. An unsolicited email demanding immediate action through an embedded link should be treated as suspicious even when it cites a real component, vulnerability class, or product model.
Practical defenses focus on isolating sensitive accounts
Users who purchased a hardware wallet should expect impersonation attempts after major vendor or logistics incidents, particularly if their email address was exposed. Strong spam filters can reduce the number of fraudulent messages that reach an inbox, while a dedicated email address for product purchases can limit the damage if a retailer or service provider suffers a breach.
Package privacy also deserves consideration. Customers concerned about exposing a home address in future purchases may choose delivery arrangements such as a post office box or another lawful pickup option offered by a carrier. That will not eliminate phishing risks, but it can reduce the amount of personal information attached to an order.
Trezor’s latest alert demonstrates why email trust cannot rest only on the sender field. When attackers gain access to a legitimate communication channel, the most reliable defense remains independent verification: navigate directly to the wallet maker’s official site, check the device’s own update prompts, and keep recovery credentials offline.
Want to stay safe from similar scams? Read our guide What is Phishing and How Does It Work to protect your crypto assets.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
