Trezor said on Sept. 9 that a third-party email service provider used by the hardware wallet company had been breached, and the intrusion was then used to send phishing emails impersonating official security notices. The attackers also used mail infrastructure tied to legitimate Trezor domains, which made the messages look very close to authentic company communications.

Fake STM32 vulnerability alert used as lure
The phishing emails largely carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability." The messages claimed that STM32 microcontrollers used in Trezor devices had a serious randomness and entropy flaw that could sharply reduce the security of users’ wallet backups, and urged recipients to carry out an immediate security check.
Trezor later said publicly that the alert did not come from the company and that the message was part of a phishing attack. It told users not to click any links in the emails and not to enter any wallet information. The company said it had shut down the affected domain and was investigating how the attackers obtained access to systems associated with its legitimate domain.
Emails appeared to come through trusted channels
Some users who received the emails posted message headers on Trezor’s official forum showing that the emails were sent through mailing.trezor.io. Other users said the messages passed common sender verification checks including SPF, DKIM, and DMARC.
That suggests this was not a simple case of spoofing a trezor.io address with lookalike characters. Instead, the attack appears to have involved access to a third-party mail system and the use of an already trusted delivery chain.
Independent security research also said some malicious links initially redirected through Trezor’s mail-tracking subdomain. In practice, that means even users who checked the sender address or hovered over links may not have been able to spot the problem right away.
The same research pointed to Brevo as the email platform involved. Trezor, however, has not formally named the breached provider, so the vendor’s identity remains unconfirmed by the company.
Another third-party risk event follows the earlier ShipMonk breach
The phishing incident came only weeks after Trezor’s previous third-party supply-chain data exposure. In August, Trezor disclosed that logistics partner ShipMonk had been breached. The company initially said the names, email addresses, phone numbers, and shipping addresses of 11,742 customers had been exposed, while another 1,947 people had part of their information leaked.
In an update issued in early September, Trezor said it found that ShipMonk’s systems still held old order data that should have been deleted under the contract. That added about 67,000 affected U.S. customers and brought the total number of affected users to about 81,000.
The leaked data included names, email addresses, phone numbers, delivery addresses, and order numbers. At the time, Trezor specifically warned that the information could be used for more targeted phishing emails, phone scams, and even in-person social engineering attempts.
There is still no public evidence showing that the ShipMonk data leak and the latest breach involving the third-party email service were carried out by the same attackers. It is also not clear whether the recipient list for the latest phishing emails came from previously leaked data.
Trezor says it will not ask for wallet backup, PIN, password, or codes
The key warning from this incident is that traditional ways of spotting phishing emails are becoming less reliable. Trezor’s official security guidance has long told users never to enter or share their recovery seed or wallet backup online with anyone.
Trezor said it will not proactively ask users to provide wallet backups, PINs, passwords, or verification codes. Any message asking a user to "verify" a mnemonic phrase or enter a wallet backup on a webpage should be treated as a scam.
That means an email that appears to come from an official domain, passes SPF or DKIM checks, or even links first to an official subdomain still should not be treated as trustworthy on that basis alone.
For the hardware wallet sector, the case also shows that cold storage does not remove every risk. Private keys can remain offline, but customer databases, logistics partners, support platforms, and email services still sit inside a conventional cloud-based supply chain. Attackers do not necessarily need to break the hardware wallet itself. If they can persuade a holder to hand over a seed phrase, they can still take control of the assets.
As of Sept. 10, Trezor had not disclosed how many people received the phishing emails, the name of the third-party email provider, or whether any users had suffered crypto asset losses as a result of the incident. The investigation is ongoing.

