Trezor says third-party email provider was breached in phishing campaign using fake STM32 flaw alert

Trezor says third-party email provider was breached in phishing campaign using fake STM32 flaw alert

N
News Editor
2026-09-10 07:15:14
Hardware wallet maker Trezor said on Sept. 9 that one of its third-party email service providers had been breached, allowing attackers to send phishing emails that appeared to come through legitimate Trezor-linked mail infrastructure. The messages used the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and claimed that devices using STM32 microcontrollers faced a serious entropy flaw that could weaken wallet backup security. Trezor said the warning was fake, told users not to click any links or enter wallet information, and added that it had shut down the affected domain while investigating how access to systems tied to its legitimate domain was obtained. Users who posted email headers on Trezor’s official forum said the messages were sent via mailing.trezor.io, while some also reported that the emails passed SPF, DKIM, and DMARC checks. Independent security research said some malicious links initially redirected through a Trezor mail-tracking subdomain. Separate research pointed to Brevo as the platform involved, but Trezor has not officially named the breached vendor. The incident follows Trezor’s earlier disclosure that logistics partner ShipMonk had been breached, a case that later expanded to about 81,000 affected customers after the company found old order data had been retained in ShipMonk’s systems.

Trezor said on Sept. 9 that a third-party email service provider used by the hardware wallet company had been breached, and the intrusion was then used to send phishing emails impersonating official security notices. The attackers also used mail infrastructure tied to legitimate Trezor domains, which made the messages look very close to authentic company communications.

Trezor says third-party email provider was breached in phishing campaign using fake STM32 flaw alert 2

Fake STM32 vulnerability alert used as lure

The phishing emails largely carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability." The messages claimed that STM32 microcontrollers used in Trezor devices had a serious randomness and entropy flaw that could sharply reduce the security of users’ wallet backups, and urged recipients to carry out an immediate security check.

Trezor later said publicly that the alert did not come from the company and that the message was part of a phishing attack. It told users not to click any links in the emails and not to enter any wallet information. The company said it had shut down the affected domain and was investigating how the attackers obtained access to systems associated with its legitimate domain.

Emails appeared to come through trusted channels

Some users who received the emails posted message headers on Trezor’s official forum showing that the emails were sent through mailing.trezor.io. Other users said the messages passed common sender verification checks including SPF, DKIM, and DMARC.

That suggests this was not a simple case of spoofing a trezor.io address with lookalike characters. Instead, the attack appears to have involved access to a third-party mail system and the use of an already trusted delivery chain.

Independent security research also said some malicious links initially redirected through Trezor’s mail-tracking subdomain. In practice, that means even users who checked the sender address or hovered over links may not have been able to spot the problem right away.

The same research pointed to Brevo as the email platform involved. Trezor, however, has not formally named the breached provider, so the vendor’s identity remains unconfirmed by the company.

Another third-party risk event follows the earlier ShipMonk breach

The phishing incident came only weeks after Trezor’s previous third-party supply-chain data exposure. In August, Trezor disclosed that logistics partner ShipMonk had been breached. The company initially said the names, email addresses, phone numbers, and shipping addresses of 11,742 customers had been exposed, while another 1,947 people had part of their information leaked.

In an update issued in early September, Trezor said it found that ShipMonk’s systems still held old order data that should have been deleted under the contract. That added about 67,000 affected U.S. customers and brought the total number of affected users to about 81,000.

The leaked data included names, email addresses, phone numbers, delivery addresses, and order numbers. At the time, Trezor specifically warned that the information could be used for more targeted phishing emails, phone scams, and even in-person social engineering attempts.

There is still no public evidence showing that the ShipMonk data leak and the latest breach involving the third-party email service were carried out by the same attackers. It is also not clear whether the recipient list for the latest phishing emails came from previously leaked data.

Trezor says it will not ask for wallet backup, PIN, password, or codes

The key warning from this incident is that traditional ways of spotting phishing emails are becoming less reliable. Trezor’s official security guidance has long told users never to enter or share their recovery seed or wallet backup online with anyone.

Trezor said it will not proactively ask users to provide wallet backups, PINs, passwords, or verification codes. Any message asking a user to "verify" a mnemonic phrase or enter a wallet backup on a webpage should be treated as a scam.

That means an email that appears to come from an official domain, passes SPF or DKIM checks, or even links first to an official subdomain still should not be treated as trustworthy on that basis alone.

For the hardware wallet sector, the case also shows that cold storage does not remove every risk. Private keys can remain offline, but customer databases, logistics partners, support platforms, and email services still sit inside a conventional cloud-based supply chain. Attackers do not necessarily need to break the hardware wallet itself. If they can persuade a holder to hand over a seed phrase, they can still take control of the assets.

As of Sept. 10, Trezor had not disclosed how many people received the phishing emails, the name of the third-party email provider, or whether any users had suffered crypto asset losses as a result of the incident. The investigation is ongoing.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.