Hardware wallet maker Trezor confirmed this week that criminals broke into a third-party email provider and used it to blast phishing messages straight out of the company’s own official domain, a detail that made the scam unusually convincing. The Trezor phishing attack hit inboxes with a fake security alert warning of a hardware flaw, and the company says it has since shut down the malicious infrastructure while it investigates how attackers gained that level of access.
Key takeaways
- Trezor confirmed its external email service provider was compromised, letting attackers send phishing emails from its legitimate domain.
- The fake message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” falsely claimed a hardware defect threatened users’ funds.
- Swiss rival BitBox reported identical phishing emails landing on the same day, pointing to a possible shared vulnerability.
- Casa’s CEO and Chief Security Officer said the messages came from real servers, not spoofed addresses, suggesting a shared marketing platform was breached.
- No confirmed cryptocurrency losses have been tied to the phishing campaign as of publication.
Trezor Email System Breach Enables Phishing Attack
A compromised email vendor is what allowed the fraudulent messages to slip past normal spam filters and land in inboxes carrying Trezor‘s real credentials. On Wednesday, the company acknowledged that its external email service provider had been infiltrated, giving attackers a direct channel to distribute phishing emails that looked, on the surface, completely authentic.
Phishing Emails Exploit Official Domain and Credentials
Bearing the subject line “Critical Security Alert: STM32 Entropy Vulnerability,” the deceptive email falsely warned that a core hardware flaw in Trezor devices might undermine the randomness underlying recovery seed phrases, a fear-based tactic meant to lure users into clicking malicious links while pretending to safeguard their crypto.
Cryptocurrency analyst Marcello Paz, who posts online as MHPaz, shared screenshots of the email showing it asked customers to update their hardware wallets because of a “critical” flaw supposedly affecting newer devices. Unlike typical phishing attempts that rely on lookalike addresses, this email carried genuine domain credentials and digital signatures, which is exactly what made it dangerous. That detail matters for anyone tracking hardware wallet security: when a scam email passes standard authentication checks, the usual advice to “check the sender address” simply stops working.
Immediate Company Response and Domain Deactivation
Trezor moved quickly once the phishing wave was flagged. “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” the company wrote on X.
According to Trezor, the malicious domain distributing the emails has since been deactivated, and an investigation into the breach is now underway, including how hackers managed to route messages through the company’s legitimate infrastructure.
BitBox Users and Casa Executives Point to Shared Infrastructure
This wasn’t an isolated incident aimed only at Trezor customers. On the same day, Switzerland-based hardware wallet maker BitBox confirmed that identical phishing emails had reached its own user base, a strong signal that the breach may extend beyond a single company’s systems.
BitBox Confirms Identical Phishing Messages
BitBox’s confirmation that its customers received the exact same fraudulent alert suggests the compromised email infrastructure serves more than one brand in the hardware wallet space. That overlap is significant: if multiple wallet manufacturers rely on the same third-party email or marketing platform, a single breach can ripple across an entire industry segment rather than staying contained to one company.
Casa’s Nick Neuman and Jameson Lopp Weigh In
Casa CEO Nick Neuman speculated on X that a shared email marketing platform was the likely point of entry. “Stay frosty and don’t trust provider emails that try to get you to take actions via sketchy looking links,” he warned.
Casa’s Chief Security Officer, Jameson Lopp, reinforced that message, emphasizing that attackers likely compromised email infrastructure used by several wallet manufacturers at once. He noted the messages weren’t spoofed at all — they were transmitted from legitimate server addresses, which explains why the emails carried valid credentials and passed authentication checks that would normally catch a fake.
A Pattern of Security Challenges for Hardware Wallets
This phishing episode lands on top of an already rough stretch for Trezor and the broader hardware wallet industry. Only a month earlier, the firm revealed that its logistics partner, ShipMonk, had suffered a breach exposing customer information; Trezor first reported that roughly 13,700 customers had their names, cities, and email addresses exposed, then admitted earlier this month that an additional 67,000 U.S. customers were hit by the same incident, pushing the overall count to nearly 80,689 individuals whose data—including phone numbers and home delivery addresses—was compromised.
At the time, Trezor warned that the leaked information could fuel more sophisticated phishing campaigns down the line. This week’s attack appears to validate that concern.
Separately, in June, Ledger’s Donjon security research team disclosed a lab-identified hardware weakness in the TROPIC01 chip used inside the Trezor Safe 7, demonstrating a laser-based attack that bypassed firmware verification in controlled conditions. Trezor said at the time that no user funds were at risk from that particular flaw. Security analysts also believe the timing of the phishing emails was chosen to exploit lingering anxiety from the recent Coldcard security flaw, which reportedly resulted in losses exceeding $130 million in Bitcoin.
Ongoing Investigation and What Users Should Do Now
Why does this matter beyond one email inbox? Because it exposes a structural weak point in crypto security: even wallets themselves stay untouched while the surrounding communication channels — email providers, marketing platforms, shipping partners — become the entry point for attackers. That shifts the burden of vigilance onto users, who can no longer rely solely on checking whether an email “looks official.”
Security specialists urge owners of hardware wallets not to click on any security-related emails purportedly from wallet makers, and instead to confirm such alerts by going straight to the company’s official site; so far, no verified crypto losses have been linked to this phishing campaign, though the probe into the breach’s origin and its full scope remains ongoing.
FAQ
How did attackers send phishing emails from Trezor’s official domain?
Attackers compromised Trezor’s external email service provider, which allowed them to send phishing emails that appeared to come from legitimate Trezor communication channels.
What was the false claim made in the phishing emails targeting Trezor users?
The phishing emails falsely claimed there was a critical hardware vulnerability called the “STM32 Entropy Vulnerability” that was compromising wallet security.
Have any cryptocurrency assets been lost due to this phishing attack?
As of this publication, no confirmed cryptocurrency losses have been attributed to the phishing operation.
What precautions should hardware wallet users take after this phishing attack?
Users should avoid clicking on suspicious links in security-related emails and independently verify any alerts by going directly to the official company website rather than trusting links sent by email.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.




Be the first to comment