Two hardware wallet makers’ own email systems turned into phishing weapons
Trezor confirmed on September 9 that its third-party email provider was breached, letting attackers send phishing emails from Trezor’s real domain. The fake email, titled “Critical Security A
A
AnonymousCryptoCompass newsroom
September 10, 2026
2 min read
NEWS
CryptoCompass editorial visual for altcoins coverage.
Trezor confirmed on September 9 that its third-party email provider was breached, letting attackers send phishing emails from Trezor’s real domain.
The fake email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” urged recipients to click a link.
BitBox reported a near-identical phishing campaign the same day; Trezor has since taken down the compromised domain and is investigating.
Trezor disclosed on X on Wednesday, September 9, that its email provider, a third-party vendor rather than Trezor’s own infrastructure, had been compromised. That let attackers send phishing emails that appeared to come from Trezor’s legitimate domain, making them far harder to spot than a typical spoofed sender address.
The bait was a fake warning titled “Critical Security Alert: STM32 Entropy Vulnerability,” referencing the microcontroller chip used in Trezor’s hardware wallets, a choice of subject line designed to sound exactly like the kind of alert a security-conscious user would feel obligated to click.
“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”
BitBox, a competing hardware wallet maker, reported a nearly identical phishing wave hitting its own customers on the same day, suggesting either a coordinated campaign against the hardware wallet sector broadly or attackers reusing a successful template across multiple targets once it worked once.
This isn’t Trezor’s first brush with a third-party breach this year. In August, a compromise at its shipping provider, ShipMonk, exposed personal information for roughly 13,700 customers before expanding to cover 67,000 more US customers. Two breaches at two different vendors within a month of each other point to the same underlying problem: a hardware wallet can be cryptographically secure while the company’s ordinary business vendors, shipping and email among them, remain a much softer target.
Blockstream has reportedly refused a Liquid hacker's $50 million bounty demand, a claim that circulated in the wake of a security incident on the Bitcoin sidechain but that no verified source
Choosing the Right Crypto Exchange Listing: Top Factors to Know People have seen this happen before, right? A random coin gets added to a big exchange, and suddenly everyone's talking about i
Developers plan to deploy the next major Ethereum network upgrade on the Sepolia testnet ahead of a future mainnet rollout. Ethereum's development community has set October 6 as the target da