Trezor, Users need to be vigilant for new phishing activities after third-party email service providers are attacked
Hardware wallet maker Trezor has warned its users to be aware of a new round of phishing attacks after being attacked by third-party email service providers. The attacker sent a fake email disguised as a "critical chip security warning" specifically targeting cryptocurrency users. The company said this was the third vendor-triggered security incident in the past four weeks.
Trezor has invalidated the domain name used in the phishing campaign and is investigating how the attacker gained access to the company's legitimate domain name. According to Trezor's announcement, the user's hardware wallets, private keys, and recovery mnemonic backup were not affected by the attack.
Why are data breaches in the cryptocurrency market frequent?
This incident follows a security breach in ShipMonk, Trezor's order delivery service provider, on August 10. In an update on September 4, the company noted that the number of users affected by the incident has exceeded 80,000. In ShipMonk's data breach, personal information such as customers 'names, phone numbers and home addresses was exposed.
When reporting the matter back in August, Trezor had pointed out that the device itself was secure, but the risk of identity theft and fraud had increased. Subsequently, some users reported receiving suspicious phone calls and physical letters.
This is not the first time Trezor has faced risks posed by third parties. Previously, the company warned about 66,000 users after its support portal was hacked in 2024. In addition, rival hardware wallet brand SafePal also attracted attention last month when about 40,000 customer records were leaked.
Why are forged STM32 warnings so realistic?
The email sent by the attacker contained a critical security warning titled "STM32 Entropy Vulnerability." STM32 is the name of the small chip family used in Trezor devices. The term "entropy" refers to the random mechanism that the wallet relies on when generating recovery mnemonic words. Because weak random numbers can indeed raise serious security issues, attackers chose a topic that technically seemed a real threat to mislead users into believing they were facing real danger.
Trezor clearly pointed out that the third-party email provider had been compromised and that the relevant message was not sent by the company's official, and warned users not to click on the link in the email.
What action should Trezor users take now?
- Never click on suspicious links: Users should avoid clicking on any unexpected links in emails from Trezor. Messages that contain the word "STM32" or "entropy" should be treated with extreme caution.
- Protect core certificates: Never enter your recovery mnemonic or device password on any website.
- Stay vigilant: Unanticipated phone calls and physical letters should be considered suspicious until verified.
- Verification through official channels: The safest way to get authentic announcements is to visit Trezor's official website or its verified X (original Twitter) account.
- Emergency response measures: If a user accidentally enters a recovery mnemonic on a suspicious link, the assets should be immediately transferred to a new, secure wallet.
Does BitBox face the same risks?
A similar incident occurred with BitBox. BitBox, a Swiss-based Bitcoin hardware wallet company, has announced that its newsletter subscribers may have been compromised, leading to an increase in phishing messages sent to subscribers. Preliminary investigations revealed that the attacker appeared to have targeted multiple bitcoin-related businesses using the same news communication provider. BitBox has notified its subscribers and contacted the service provider, while reporting the phishing domain name.
Although some malicious links were closed within a short period of time, the investigation continues. These developments show that digital asset security depends not only on the device itself, but also on third-party services that manage user data.
The cases of Trezor and BitBox show that impersonating formal corporate communications can be extremely deceptive. Therefore, users must protect the recovery mnemonic words and avoid hasty operations when faced with suspicious information.
This content does not constitute any investment advice. There are high risks in the market, please conduct independent research before making an investment decision.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC