Skip to content
  • BTC$75,403−3.13%
  • ETH$2,390−4.86%
  • SOL$96.38−5.55%
  • XRP$1.27−10.54%
  • BNB$708.84−1.80%
  • DOGE$0.0795−5.18%
  • ADA$0.1925−7.38%
  • LINK$10.78−6.91%
Technology

Trezor says phishing email came from its own domain

A breach at a third-party email provider let attackers send a fake chip-vulnerability alert from Trezor's own domain, passing authentication checks.

Rare Dollar Newsroom 3 min read
A person holds a scam alert sign beside an open laptop, illustrating a phishing campaign.
Pexels

In this story

  • BTC $75,403 −3.13%

Trezor, the Czech maker of bitcoin hardware wallets, said a breach at a third-party email provider allowed attackers to send a phishing message from its own domain on Wednesday — a campaign that also hit at least one other hardware wallet company.

“Our third-party e-mail provider has been breached,” Trezor wrote in a post on X on September 9. “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.”

The message passed the usual checks

The email addressed recipients as customers and carried the subject line Trezor flagged. According to ForkLog, which cited a recipient who published screenshots, the message displayed a “Trezor Security” sender name, used a return path at mailing.trezor.io, was sent through the email marketing platform Sendinblue, and passed Gmail’s SPF, DKIM and DMARC authentication checks.

That combination is what makes the campaign notable. Authentication records exist to prove an email really came from the domain it claims; here the sending infrastructure appears to have been authorised by that domain, so a recipient inspecting the sender address would find nothing wrong. The Block reported that Trezor is investigating how the attackers obtained access to its legitimate domain.

The lure: a fake entropy warning

The phishing email claimed to disclose a vulnerability in the random-number generation of STM32 microcontrollers. Entropy is the unpredictability a wallet uses to derive the recovery phrase that ultimately controls its funds, which gives a “critical entropy vulnerability” warning a plausible hold on the audience it targeted: people who hold their own keys.

BeInCrypto, citing the incident, reported that wallets, keys and recovery backups were not exposed.

A shared newsletter provider

BitBox, a Swiss bitcoin hardware wallet maker, reported a similar phishing email reaching its newsletter subscribers the same day. BitBox said a preliminary review suggested its newsletter provider had likely been compromised, and that multiple other bitcoin companies were targeted in what appeared to be a campaign against companies sharing the same provider.

The pattern — attackers compromising a vendor that a trusted brand has already whitelisted for bulk mail — is one of the harder ones for recipients to defend against, because the failure happens upstream of the message they receive.

Third vendor failure in weeks

The email incident follows two other breaches at outside suppliers used by Trezor. On August 13 the company disclosed that a breach at shipping provider ShipMonk had exposed personal data belonging to roughly 13,700 customers; in early September it said a further 67,000 US customers were affected by the same incident, according to The Block.

Hardware wallet makers have drawn repeated attention from attackers precisely because their users tend to be holders of significant balances. In June, Ledger’s Donjon research team demonstrated a lab-based laser attack that bypassed firmware verification on the TROPIC01 chip used in the Trezor Safe 7; Trezor said at the time that no user funds were at risk.

Sources

  1. Trezor on X: third-party email provider breached (September 9, 2026)
  2. BitBox on X: newsletter provider compromise (September 9, 2026)
  3. The Block: Trezor says third-party security breach led to phishing emails from legitimate domain
  4. ForkLog: Hackers target Trezor users through compromised email service
  5. The Block: Trezor says ShipMonk breach affected another 67,000 customers