Search the site
Press ESC to close
LIVE
Loading...
Updating...

Trezor Issues Security Alert Following Third-Party Email Service Breach

Pieter van Meer
Fact-checked
2 min read
359 words
Share

The prominent hardware wallet manufacturer Trezor has issued an urgent warning to its user base regarding a sophisticated phishing campaign initiated on September 10, 2026. The security incident stems from a compromise of a third-party email service provider used by the company, leading to the dissemination of unauthorized communications. Trezor has clarified that the integrity of its hardware devices remains intact, but users are urged to exercise extreme caution when handling unsolicited emails purportedly sent from official domains.

Details of the Phishing Campaign and Malicious Content

The attackers distributed fraudulent emails featuring the subject line "Critical Security Alert: STM32 Entropy Vulnerability." To increase the appearance of legitimacy, the malicious actors utilized a forged sender address, [email protected], attempting to deceive recipients into believing the message originated from the official support team. The content of the email falsely claimed a technical flaw in the STM32 microcontrollers—the chips used in various Trezor models—to prompt users to click on external links.

  • Targeted Subject: Critical Security Alert: STM32 Entropy Vulnerability.
  • Spoofed Address: [email protected].
  • Primary Goal: Directing users to malicious domains to harvest seed phrases or sensitive data.

Response Measures and Current Status of Investigation

Trezor’s security team acted quickly to mitigate the threat by ensuring the malicious domain associated with the phishing links was taken offline. The company has confirmed that an intensive investigation is currently underway to determine the full scope of the breach at the third-party provider.

"This email is not official communication and reminds users not to click on any links within it", the company stated in its official advisory.

Hardware wallet users are frequently targeted by such social engineering tactics, which aim to bypass technical security measures by exploiting human error.

As of the latest update, there is no evidence that the Trezor Suite app or the firm’s internal systems have been breached. Investors and holders of assets like Bitcoin (BTC) and Ethereum (ETH) are reminded that official support will never request a recovery seed or PIN via email. Trezor continues to monitor the situation and advises users to rely only on official social media channels for further security updates.

Frequently Asked Questions

Quick answers to the most common questions about this topic.