Trezor claims that a third-party email leak caused attackers to use its official domain name to send phishing emails.
Trezor said that a third-party email service leak allowed attackers to send phishing messages from its hardware wallet manufacturer's own domain name. This is a rare upgrade that deprives users of the ability to identify fake emails, usually by checking the sender's address. The Trezor email leak follows another logistics provider incident that has lasted for months, highlighting that the risks faced by wallet holders now lie largely outside the provider's own infrastructure.
Details of the incident disclosed by Trezor
The core details of the Trezor email leak are troubling: The vulnerability did not appear in Trezor's hardware or core systems, but was located at a third-party email provider. However, this was enough for attackers to weaponize the company's trusted communication channels. According to Unchained, Trezor said the leak allowed attackers to push phishing emails to users.
This malicious activity used a sense of urgency as bait, using "Critical Security Alert: STM32 Entropy Vulnerability" as the subject of the email to prompt recipients to take action. Trezor warns recipients not to click on links within messages. According to unconfirmed reports, the excuse is that the real STM32 entropy flaw requires users to update the device via instructions in the email, but this is itself phishing bait rather than a verified security vulnerability.
Trezor's existing security guidelines are the defenses relevant here: Official support will never ask for mnemonic words (recovery seeds), and users should not enter wallet backups without first initiating a recovery procedure and confirming it on the device. Attackers often covet wallet backup because once a mnemonic phrase is entered on a malicious page, control of the funds is completely transferred to the attacker.
The attacker used Trezor's own domain name to send phishing emails
The difference between this operation and regular cryptocurrency phishing attacks lies in the sender. According to reports, the news did not come from imitation domain names or forged display names, but came directly from Trezor's own domain name. This means that in this case, the usual recommendation to users to double-check addresses provides little protection.
Existing reports do not include samples of messages, specific domain names or technical delivery mechanisms, so the exact path from the provider's leak to the generation of seemingly authenticated messages remains undescribed. Trezor was not the only brand targeted: BitBox warned its customers about similar impersonation activities on the same day, an industry reaction reported by Unchained rather than an independent BitBox statement.
What is unclear about the Trezor email leak
Scope, impact and response
Existing reports fail to determine how many recipients received phishing emails, whether there was financial loss, the identity of the email provider, and the current status of the malicious domain name. These gaps reflect limitations of the available materials rather than evidence that the incident was minor or fully controlled.
Background information comes from another incident disclosed in more detail by Trezor. In its official Frequently Asked Questions (FAQ) updated on September 4, 2026, Trezor stated that 80,689 customers were affected by the leak from logistics provider ShipMonk. Although headlines suggest there is no merger total, the company has announced the number.
The ShipMonk leak was originally released on August 13 and was updated after Trezor learned on September 2 that older order data was also involved. The initial list listed 11,742 fully exposed customers and 1,947 partially exposed customers. The September update added approximately 67,000 U.S. customers whose order data (including names, emails, phone numbers, shipping addresses and order numbers) from November 2019 to August 2021 was retained despite a previous explicit commitment to follow a 90-day retention window and multiple written guarantees of deletion.
Trezor said its own systems were not compromised and its devices remained secure during the ShipMonk incident, but the statement did not extend to subsequent attacks by email providers. There is no evidence that the logistics breach is causally related to current phishing activities, and the claim that ShipMonk data provides a target has not been verified.
This model has become familiar in the industry, and peers such as SafePal have also disclosed the leakage of order information from nearly 40,000 customers. The main thread connecting these events is that the hardware wallet remains secure by design, but the surrounding customer data and communication channels held by logistics and email providers are increasingly becoming more vulnerable targets.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
ETH