The manufacturer of Trezor wallets has warned users about a new phishing campaign following a reported incident involving its third-party email service provider, according to Coin68. Messages appearing to come from the company’s own domain can be harder to distinguish from genuine communications than ordinary impersonation emails.
A fake warning about an STM32 vulnerability
The fraudulent email carries the subject line “Critical Security Alert: STM32 Entropy Vulnerability”. It claims that Trezor engineers discovered a serious flaw in the STM32 microcontroller used in the company’s devices. The attackers also claim that roughly one in four Trezor wallets is affected, leaving their recovery phrases insufficiently random and potentially predictable. These are claims made by the scammers, not an established finding about Trezor devices.
The message appears designed to exploit concern following the recent Coldcard entropy incident, which involved the generation of vulnerable recovery seeds. Trezor has discussed that separate incident in its technical analysis. By presenting a similar scenario, the attackers seek to frighten users into following their instructions.
The email then directs recipients to an attached link to supposedly update their devices and fix the problem. According to the supplied Coin68 report, Trezor said the warning was fraudulent and that it had issued no such security notice.
The same report says Trezor took down the phishing domain and began investigating how its legitimate email domain had been used. This concerns the domain hosting the scam, rather than the closure of Trezor’s official website.
BitBox users reportedly receive similar messages
According to FORECK.INFO, Casa co-founder and CEO Nick Neuman suggested that a compromised email marketing provider was a likely explanation, rather than a breach of Trezor’s internal systems. He also cautioned against acting immediately on urgent emails, even when they appear to come from an official address.
Bitcoin security researcher Jameson Lopp reportedly noted that BitBox users had received similar phishing messages. This raised the possibility of a shared email provider being compromised, although that explanation should not be treated as a confirmed conclusion.
Coin68 also reports that BitBox acknowledged fraudulent emails claiming its devices had a vulnerability and needed a firmware update. The messages reportedly used the company’s legitimate domain and email signature, making them look like genuine notices.
Earlier incidents provide context
In August 2026, Trezor disclosed a separate breach at shipping provider ShipMonk. Its official update initially listed 13,689 affected customers. On September 4, Trezor reported approximately 67,000 additional US customers, bringing the combined figure to roughly 80,700. Exposed information included names, email addresses and, for customers with full exposure, phone numbers and shipping addresses. Such data can facilitate targeted phishing; this does not establish a connection between the two incidents.
Separately, in June 2026, Trezor disclosed research involving the TROPIC01 chip used in Safe 7. Ledger Donjon had reported its findings to Tropic Square in January. The laboratory attack involved laser fault injection, while subsequent work explored running custom chip firmware. In its June response, Trezor said compromising this chip alone did not expose the wallet’s PIN, funds or recovery backup.
What users should remember
Trezor’s phishing guidance explains how scammers use urgent security claims to obtain wallet backups. Never share your recovery phrase or enter it into a website reached through an unsolicited email. Check any claimed update through the manufacturer’s official application and independently verified channels.