Trezor warned users on September 9, 2026, after attackers exploited its third-party email provider to distribute phishing messages falsely claiming a critical security vulnerability. The Trezor wallet itself was not compromised by the attack.
The fraudulent email carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and claimed Trezor engineers had discovered a design flaw in STM32 chips used in its products. The message warned that one out of four devices could become compromised and that recovery phrases might lack sufficient randomness.
Emails Passed Authentication Checks
The phishing campaign's effectiveness stemmed partly from its delivery method. One recipient reported receiving the email from a legitimate Trezor sending address that passed DKIM, SPF, and DMARC authentication checks, following Sendinblue's campaign infrastructure.
Trezor identified the message as fraudulent and warned users not to click embedded links. The company stopped the domain used for the alerts and began investigating how attackers accessed its legitimate email infrastructure. Trezor's public alert was issued around 4:30 PM Eastern time on September 9, hours after users began reporting the suspicious emails.
Broader Vulnerability in Hardware Wallet Infrastructure
Casa co-founder and CEO Nick Neuman noted a similar trend affecting BitBox users, suggesting a common marketing email provider may have been breached. The incident underscores a wider vulnerability: hardware wallet manufacturers can secure their devices but remain exposed through third-party services including email providers, shipping companies, and payment processors.
Leaked customer data from hardware wallet breaches has fueled increasingly sophisticated phishing campaigns. Chainalysis reported that crypto scams and fraud stole $17 billion in 2025, with impersonation scams growing more than 1,400% year over year. Purchase records containing names, emails, phone numbers, and home addresses provide criminals with context to craft convincing impersonation attempts.
Data Breaches Versus Device Exploits
Data breaches affecting hardware wallet makers differ from device exploits. While breaches compromise identity and contact information, device exploits potentially threaten financial assets directly. In 2026, multiple hardware wallet companies experienced data breaches: SafePal disclosed an authorization error exposing approximately 39,798 customers' order data; Trezor's ShipMonk breach eventually affected 80,689 customers including old US records from 2019 to 2021; and Ledger's Global-e incident in January exposed customer order details and contact information.
The Coldcard situation stands apart as a device exploit rather than a data breach. According to Galaxy Research on August 14, the exploit confirmed 190 direct victims, more than 86,000 affected addresses, and at least $112.7 million worth of stolen cryptocurrency due to firmware flaws, with some estimates reaching $130 million.
Security Perimeter Expanded
Trezor's latest incident illustrates that hardware wallet security now encompasses the systems surrounding the device itself. Attackers increasingly need only one convincing message from a trusted-appearing source to breach user confidence and gain access to sensitive information.


