EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Bitcoin wallet maker Trezor says hackers compromised its email provider

2026-09-10 08:11:29
Bookmark

Trezor warns users that third-party mailboxes have been compromised and phishing emails that fake "emergency security alerts" are spreading

On Wednesday, hardware wallet maker Trezor issued a warning that hackers had hacked into its third-party email provider and used the channel to distribute phishing emails disguised as "critical security warnings."

Trezor issued a statement on Platform X (formerly Twitter):"Please note that the email titled 'Critical Security Alert: STM32 Entropy Vulnerability' did not come from us, it was a phishing attempt. Don't click on any links."

Trezor said it had taken technical measures to shut down the domain name used in the attack and was investigating how hackers gained access to its legitimate domain name.

Fake email claims serious hardware vulnerability found

This fake Trezor email claims that the company's engineers discovered a "critical hardware-level vulnerability" in the STM32 microcontroller used in its devices. The email further falsely claimed that the flaw affected about a quarter of the equipment and could lead to insufficient randomness (i.e. entropy) in recovering mnemonic words.

The move is suspected to take advantage of user panic triggered by the recent attack on Coldcard's device, which resulted in more than US$13 million in Bitcoin losses.

Official response and industry warning

Trezo issued an official statement around 4:30 pm Easter time, refuting the email as fraud and reminding users. However, hours had passed since multiple users reported receiving phishing emails that appeared to come from Trezor's official email address.

Casa co-founder and CEO Nick Neuman pointed out that the attack may not be limited to Trezor, and said he had received similar feedback from BitBox users. He wrote on the X platform: "It is very likely that a marketing email provider was compromised. Please be vigilant and don't believe unofficial emails that try to induce you to take action through suspicious links."

Jameson Lopp, a Bitcoin security researcher and Casa's chief security officer, issued a similar warning. He posted: "Threat actors may have compromised the email providers used by Trezor and BitBox. There are currently malicious emails claiming that the two companies 'devices contain bad random number generators (RNG) and require security updates, but these emails do not appear to be forged. In fact, officials have not issued such safety recommendations!"

Review of past security incidents

In August this year, Trezor and Foundation, another cryptocurrency hardware wallet manufacturer, jointly warned users to guard against phishing attacks that took advantage of hardware wallet security anxiety, when researchers disclosed vulnerabilities affecting Coldcard devices.

In the same month, Trezor reported a data breach at its logistics provider ShipMonk, which resulted in the disclosure of personal information (including names, email addresses, phone numbers and mailing addresses) of 80,689 customers. Trezor warned at the time that the leaked information could be used in more complex phishing attacks.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP