πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
β€”β–²0.0%
News

Phishing Emails Reached Trezor Users From Trezor's Own Domain

10 Sept 2026by CryptoJazz Admin1 min read6 views
Phishing Emails Reached Trezor Users From Trezor's Own Domain

Trezor told customers on Wednesday that a third-party email provider it uses had been breached, and that a message landing in their inboxes under the subject line "Critical Security Alert: STM32 Entropy Vulnerability" did not come from the company. The email travelled the company's own mail path. It carried a trezor.io sender address. No customer funds have been reported lost. Trezor said wallets, keys and backups were never exposed.

The email that looked right

The fake message told recipients that engineers had found a hardware-level defect in the STM32 microcontrollers inside Trezor devices, and that the flaw left recovery phrases, the word list that restores a wallet, with too little randomness to be safe. Decrypt and CryptoTimes both report the email claiming roughly one in four devices was affected. CryptoTimes adds a factory defect producing 40-bit seeds, a figure no other account carries. The remedy on offer was a device update, through a link.

What made it work was plumbing more than wording. Cryptopolitan reports the messages cleared DKIM, SPF and DMARC, the checks a receiving mail server runs to decide whether a sender is genuine. They cleared because in a narrow technical sense the sender was. CryptoTimes describes the headers: a "Trezor Security" display name, help@trezor.io in the From field, and a landing page on mailing.trezor.io. That breakdown appears in CryptoTimes alone, as does its claim that the page collected extended public keys, which map a holder's addresses and balances without moving a coin. It stands unverified.

Nobody has named the provider

"Our third-party e-mail provider has been breached. Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link," Trezor said.

That statement names no company, and Trezor has not added one since. The Block and BeInCrypto both leave the provider unnamed for the same reason. Decrypt says the email headers point to Sendinblue, a marketing mail service, and Cryptopolitan names the same service. CryptoTimes attributes the identification to two outside analysts, YFarmX and Blocktrainer, gives the service its current name, Brevo, and adds that unauthorized API keys were created inside affected accounts. Sendinblue and Brevo are one company under its old and new names. None of these accounts carries a confirmation from it.

BitBox warned first

Trezor was not the only wallet maker warning users that evening. BitBox, a Swiss manufacturer, told newsletter subscribers that a similar email was circulating. On CryptoTimes' timeline BitBox posted at 20:01 UTC and expanded on it at 21:03, while Trezor's first alert came at 20:37. Decrypt puts Trezor's warning at around 4:30 p.m. Eastern, the same window read off a different clock. Casa chief executive Nick Neuman, in remarks Cryptopolitan carries, took the overlap as a sign that a shared marketing platform had been compromised. Neither company has confirmed the two campaigns ran from the same account.

The name list from August keeps growing

Trezor customers were already exposed this summer. A breach at ShipMonk, a logistics contractor, put customer records in the open in August, and the company later found 67,000 more US customers in orders from 2019 to 2021. The totals do not settle. CryptoTimes gives 13,689 in the first disclosure and, adding the later tranche, roughly 80,700 people; Decrypt and Cryptopolitan both print 80,689. Those figures do not reconcile, and no account explains the gap. The dates wobble as well, with BeInCrypto putting the incident on 10 August and CryptoTimes putting the disclosure on 13 August.

What leaked also depends on the outlet. The Block lists names, cities and email addresses. Decrypt and CryptoTimes add phone numbers and shipping addresses. Every account agrees on the part that matters most: no wallet seeds were in the data.

The invented flaw had a real cousin. An entropy bug in Coldcard firmware drained bitcoin from wallets in July. A warning about weak randomness therefore reads as plausible to anyone who followed that story. Trezor has published no account of how the provider was breached, or of when it will name the service. Until it does, customers are checking headers on their own.

Read also: Ledger Patched an Ethereum Signing Flaw, Then Fought Over the Disclosure

← All news