Trezor warns of phishing emails after breach of third-party email provider used to send alerts
Trezor warned users that hackers breached a third-party email provider and used Trezor’s legitimate email domain to send phishing messages, including an email with the subject “Critical Security Alert: STM32 Entropy Vulnerability,” urging recipients not to click links [1].
Cointelegraph reported that BitBox also warned about fake hardware wallet security alerts, and that both sets of activity appeared to have been targeted via a shared newsletter provider, while Trezor confirmed the breach at its email service [2].
Blockonomi said the breach at Trezor’s external email service provider allowed attackers to distribute fraudulent alerts using the company’s verified domain, and that Trezor disabled the affected domain and began a security investigation [3].
Cryptopolitan reported that Trezor said the phishing used the compromised email-provider setup to deliver a bogus security notice, and that Trezor’s wallet itself was not affected by the attack [4].
Yellow characterized the incident as Trezor’s second third-party security incident in about a month involving its customer base, after the phishing emails were sent from its legitimate domain following a third-party provider breach [5].
Anonymous feedback used to improve internal story ranking. No public totals are shown.
Share
Share this article
Share this article on social platforms.
Support ClusterWire
If you find ClusterWire useful, tips help cover hosting and infrastructure costs.
We record anonymous interactions with tip buttons to understand feature usage. We do not include IP addresses, user-agent strings, or wallet addresses in these tip analytics. Blockchain transactions are public and may reveal the sending address.
Sources
Review the sources used to produce this brief. Citations open the referenced material in a new tab.
- 1
- 2Trezor, BitBox warn users about fake hardware wallet security alertsCointelegraph• Sep 10, 2026
- 3Trezor Email System Compromised: Phishing Attack Exploits Official DomainBlockonomi• Sep 10, 2026
- 4Trezor warns users after hackers breach email provider to send phishing alertsCryptopolitan• Sep 10, 2026
Updates and corrections
No changes recorded in the new revision log. Earlier edits may not be included.
Topics
Related Topics
Topics identified from the sources associated with this article.