Finst

Trezor Warns After New Phishing Incident Via Email Provider

The phishing email played on a supposed STM32 chip warning, while Trezor says wallets and recovery backups were not affected. It is already the third incident involving a supplier in four weeks.

Trezor Warns After New Phishing Incident Via Email Provider

Key Takeaways

  • Trezor reported a phishing incident after attackers gained access to a third party that sends emails for the company.
  • Customers received a fake email about a critical STM32 chip warning, while wallets, keys, and recovery backups were not exposed.
  • Trezor warns people not to click links and never to enter a recovery phrase or device code; anyone who did should move their funds.

Trezor has reported another security incident after attackers gained access to a third party that sends emails for the company. After that, customers received a phishing email posing as a critical warning about an STM32 chip, while Trezor says wallets, keys, and recovery backups were not exposed.

Third Party Hit Again

According to Trezor, the domain behind the campaign has now been taken offline, and the company is investigating how attackers were able to get to the legitimate domain. It is the third vendor failure in four weeks for the hardware wallet company, after earlier problems at ShipMonk, the company that ships Trezor orders.

That earlier breach started on August 10 and later led to an update on September 4, when the number of affected customers climbed above 80,000. The leaked data included names, phone numbers, and home addresses. That mainly raised the risk of targeted scams, while the hardware wallets themselves stayed safe.

Why the Email Looks Believable

The fake email referred to a so-called STM32 Entropy Vulnerability. STM32 is the chip family used in Trezor devices. Entropy is the randomness a wallet uses to create a recovery phrase, and that is exactly why this kind of warning sounds believable to many users.

Trezor warned customers not to click links in unexpected emails, especially if they mention STM32 or entropy. The company also says users should never enter a recovery phrase or device code on a website. Anyone who did should move the funds to a new wallet.

What This Means for Users

For European crypto users, this incident shows that the risk often is not in the hardware wallet itself, but in the companies around it. Earlier reports already showed that customers also received scam calls and physical letters after data breaches. That makes contact details, shipping data, and email addresses valuable to attackers targeting wallet owners.

That pattern fits broader concerns in the industry: in other incidents too, suppliers, support channels, and identity data turn out to be attractive entry points for attackers. For example, a data breach at a broker shows how quickly personal information can be abused for phishing and other targeted attacks.

Trezor also said it is working on an Anonymous Delivery option, so customers may be able to have orders delivered in the future without sharing personal data. For the EU, rollout is expected in September 2026, and for the US by the end of 2026.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.