Key PointsA security breach at Trezor’s external email service provider enabled attackers to distribute phishing messages using the company’s verified domainRecipients received fraudulent alerts about a supposed “STM32 Entropy Vulnerability” prompting immediate device updatesHardware wallet manufacturer BitBox reported identical phishing attempts targeting their customer base, indicating a broader attackTrezor immediately disabled the affected domain and initiated a comprehensive security investigationThe incident comes weeks after a ShipMonk compromise leaked personal information of more than 80,000 Trezor clientsOn Wednesday, Trezor publicly acknowledged that cybercriminals had successfully infiltrated its external email service provider. The breach enabled unauthorized parties to distribute phishing messages that appeared to originate from authentic Trezor communication channels.ALERT: Trezor warns hackers have breached its email provider and are sending phishing emails from its legitimate domain.The fake email claims a "Critical Security Alert: STM32 Entropy Vulnerability" that could expose your recovery phrase.Trezor confirms it is NOT real and… pic.twitter.com/RW3y0C4E7h— Coin Bureau (@coinbureau) September 10, 2026The fraudulent message carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” It falsely asserted that a fundamental hardware defect in Trezor wallets could compromise the randomness generation process for recovery seed phrases, thereby endangering stored cryptocurrency assets.Trezor immediately issued a warning through its X platform. “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” the organization stated.According to the company, the malicious domain has been deactivated, and a thorough investigation into the security breach is currently underway.Security analysts believe the timing of these fraudulent messages was strategically chosen to capitalize on concerns surrounding the recent Coldcard security flaw, which resulted in cryptocurrency losses exceeding $130 million in Bitcoin.BitBox Customers Similarly AffectedSwitzerland-based hardware wallet company BitBox confirmed that identical phishing emails reached its user base on the same date. This development suggests the security incident may involve multiple hardware wallet brands.Really brutal. The phishing email is written quite convincingly, and it comes from the official Trezor domain.At least tens of millions will be lost; hopefully not hundreds of millions. Insane f*ckup from Trezor. https://t.co/GBVcqBEJVh pic.twitter.com/4xw8QM8bvi— FatMan (@FatManTerra) September 9, 2026Casa CEO Nick Neuman speculated on X that a common email marketing platform was the likely breach point. “Stay frosty and don’t trust provider emails that try to get you to take actions via sketchy looking links,” he cautioned.Jameson Lopp, serving as Casa’s Chief Security Officer, reinforced these warnings. He emphasized that malicious actors likely compromised email infrastructure utilized by multiple wallet manufacturers, noting that the messages weren’t spoofed but transmitted from legitimate server addresses.Cryptocurrency analyst MHPaz published email screenshots demonstrating the messages featured official domain credentials and digital signatures that appeared completely legitimate.Recurring Security ChallengesThis incident represents the latest in a series of security challenges for Trezor. In the previous month, logistics partner ShipMonk suffered a data breach that compromised information for 80,689 customers, including full names, email addresses, telephone numbers, and physical delivery addresses.At that time, Trezor cautioned that the exposed customer information could facilitate increasingly sophisticated phishing operations. Recent events have validated these concerns.Earlier in June, Ledger’s security researchers revealed a laboratory-identified hardware weakness in the TROPIC01 chip integrated into the Trezor Safe 7 model. Trezor maintained that this particular vulnerability posed no threat to customer assets.Security experts are urging hardware wallet owners to avoid interacting with any security notification emails from wallet manufacturers until official confirmation can be obtained. Users should independently verify all alerts through direct navigation to official company websites.As of this publication, no confirmed cryptocurrency losses have been attributed to the ongoing phishing operation.The post Trezor Email System Compromised: Phishing Attack Exploits Official Domain appeared first on Blockonomi.