Trezor alerted users on Wednesday, September 9, 2026, about hackers exploiting its third-party email provider to distribute a bogus security notice. However, the Trezor wallet was unaffected by the attack. The criminals targeted something even harder to safeguard than a piece of software: the confidence of a user in an email from a trusted provider.The subject line of the warning read as follows: “Critical Security Alert: STM32 Entropy Vulnerability.” The message stated that Trezor engineers had discovered a design defect in STM32 chips used in its products. Decrypt reported that Trezor recognized the message as fake and warned readers not to click on the links.A fake flaw sent from a real addressWhat made the campaign effective was not the fabricated vulnerability but the manner in which the email was received. One recipient revealed that the email came from help@trezor.io, followed the Sendinblue campaign path, and passed the DKIM, SPF, and DMARC checks.The alert specified that one out of four devices can become compromised and that recovery phrases may not have enough randomness or entropy. This language bore a close resemblance to the issues described in the recent Coldcard attack.Trezor reported that it stopped the domain used for sending out the alerts and started probing into how the fraudsters managed to use its legitimate sending infrastructure. The company’s public alert came out right after 4:30 PM Eastern time on the 9th of September, only a few hours after its users started raising flags about the emails.The breach may reach past TrezorAccording to Nick Neuman, co-founder and CEO of Casa, there seems to be a similar trend occurring among users of BitBox and that a common marketing email provider may have been breached.That’s the larger issue. Wallet makers can make their devices more secure, but their brand can still be stolen through means they don’t completely manage, from email service providers to shipping companies and payment processors.Data breaches are not device exploitsIn a previous report by Cryptopolitan, it was revealed that phishing attempts against Ledger users have also found their way into physical mail. However, it should be noted that these cases are different from those of device exploits since a data breach compromises identity and contact information, while a device exploit may also put financial assets at risk.The attacks on hardware wallets that occurred in 2026 make this distinction clear. SafePal admitted that there was an authorization error in one of its order tracking plugins that led to the exposure of data of approximately 39,798 customers, and that seed phrases, private keys, and wallet credentials of these customers were not compromised.Trezor’s ShipMonk breach eventually increased the number of affected customers to 80,689 after the company learned that the old US order records dating back from 2019 to 2021 were also stored and exposed. Similarly, in January, the Global-e incident of Ledger also saw the exposure of the order details and contact information of its customers, with the exact number of customers not being disclosed.In its August comparison, Memeburn correctly categorized Ledger, Trezor, and SafePal under “data breaches” while identifying Coldcard as an “device exploit”. The indicated figure of 13,689 mentioned by Memeburn in reference to Trezor is, however, from before the update of Trezor on September 4.Coldcard stands apart from the rest. According to Galaxy Research on August 14, it confirmed 190 victims directly as well as more than 86,00 affected addresses and at least $112.7 million worth of stolen 1,778.84 BTC due to flaws in the firmware. Other estimates had put the possible loss near $130 million.2026 Hardware Wallet Breaches vs. Coldcard Exploit: Victims, Data Exposure and Crypto LossesLeaked context feeds industrialized phishingThe danger in a leaked shipping list is what happens next. Chainalysis estimated that crypto scams and fraud stole $17 billion in 2025, while impersonation scams grew more than 1,400% year over year. It also found that scams with on-chain links to AI vendors generated 4.5 times more revenue per operation than those without such links.A hardware-wallet purchase record can therefore become a targeting file. A name paired with an email, phone number, home address, and confirmation that someone owns a crypto-security device gives criminals the context to craft convincing emails, calls, letters or even physical approaches.The lesson from Trezor’s latest incident is not that hardware wallets failed. It is that the security perimeter now includes the systems around them, and attackers increasingly need only one trusted-looking message to break through.If you're reading this, you’re already ahead. Stay there with our newsletter.