Skip to main content
News BriefTopicSecurity

Trezor warns of phishing emails after breach of third-party email provider used to send alerts

Sep 10, 2026By ClusterWire.news· AI-assisted news brief

Trezor warned users that hackers breached a third-party email provider and used Trezor’s legitimate email domain to send phishing messages, including an email with the subject “Critical Security Alert: STM32 Entropy Vulnerability,” urging recipients not to click links [1].

Cointelegraph reported that BitBox also warned about fake hardware wallet security alerts, and that both sets of activity appeared to have been targeted via a shared newsletter provider, while Trezor confirmed the breach at its email service [2].

Blockonomi said the breach at Trezor’s external email service provider allowed attackers to distribute fraudulent alerts using the company’s verified domain, and that Trezor disabled the affected domain and began a security investigation [3].

Cryptopolitan reported that Trezor said the phishing used the compromised email-provider setup to deliver a bogus security notice, and that Trezor’s wallet itself was not affected by the attack [4].

Yellow characterized the incident as Trezor’s second third-party security incident in about a month involving its customer base, after the phishing emails were sent from its legitimate domain following a third-party provider breach [5].

Was this useful?

Anonymous feedback used to improve internal story ranking. No public totals are shown.

Share

Share this article

Share this article on social platforms.

Support ClusterWire

If you find ClusterWire useful, tips help cover hosting and infrastructure costs.

We record anonymous interactions with tip buttons to understand feature usage. We do not include IP addresses, user-agent strings, or wallet addresses in these tip analytics. Blockchain transactions are public and may reveal the sending address.

Article sources

Sources

Review the sources used to produce this brief. Citations open the referenced material in a new tab.

Updates and corrections

No changes recorded in the new revision log. Earlier edits may not be included.

Topics

Related Topics

Topics identified from the sources associated with this article.

Coverage

Latest Coverage

Latest crypto news briefs, ordered by publication time.

34h ago · AI-assisted

IOG warns users after its YouTube channel was hijacked to promote a fake Charles Hoskinson giveaway

Input Output Group (IOG) warned users to avoid its official YouTube channel after the channel was reportedly hijacked and used to air a fake Charles Hoskinson giveaway livestrea…

Read more
Sep 17, 2026 · AI-assisted

S&P Global to acquire OpenZeppelin to expand digital asset risk assessment into onchain technology

S&P Global has entered into an agreement to acquire OpenZeppelin, a smart contract security company, as part of an expansion of its digital asset risk assessment capabilities in…

Read more
Sep 14, 2026 · AI-assisted

Reports say Revolut hackers leaked customer KYC data and demanded ransom payments, including 10,000 BTC

Reports say hackers have released personal identification documents and verification selfies belonging to Revolut users and are using the data release as extortion to demand ran…

Read more
Sep 8, 2026 · AI-assisted

Cronos reports $9.19M still unrecovered after Tectonic exploit rollback reversed $111.2M

Cronos said $9.19 million remains unrecovered after an attacker borrowed $120.4 million from the Tectonic lending protocol, and validators later approved a rollback that reverse…

Read more
Sep 3, 2026 · AI-assisted

U.S. agents seize about $560,000 in cryptocurrency linked to Hamas and take over fundraising infrastructure

U.S. federal agents seized about $560,000 in cryptocurrency allegedly tied to Hamas’ military wing and took control of domains and servers used in the group’s fundraising and re…

Read more
Sep 2, 2026 · AI-assisted

Fake Claude Opus desktop app distributes RevStealer malware targeting 50+ crypto wallets on Windows

Security reporting says a fraudulent desktop application impersonating “Claude Opus 5 Free Desktop” is distributing the RevStealer malware on Windows systems [1]. The reports st…

Read more