Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider
The hardware wallet maker said a fake security alert claimed a hardware flaw could expose users’ recovery phrases.
Jason Nelson
Publisher Decrypt
Sep 9, 2026 at 11:02 PM UTC · 2 dk okuma

Key Signal
$130M+ Coldcard exploit losses
Entities
bitcoin
Last Updated
bir saat önce
- Trezor said its third-party email provider was breached and used to send phishing emails.
- The fake alert claimed an STM32 hardware flaw weakened recovery phrases on some Trezor devices.
- Security researchers said similar emails targeting BitBox users may point to a broader compromise of hardware-wallet email providers.
Hardware wallet maker Trezor warned users Wednesday that hackers breached its third-party email provider and used it to distribute a phishing email disguised as a critical security warning.
“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” Trezor wrote on X.

Trezor said it took down the domain used in the attack and is investigating how hackers gained access to its legitimate domain.
The fake Trezor email claims the company's engineers discovered a “critical hardware-level vulnerability” in STM32 microcontrollers used in its devices. It then falsely claims the defect affects an estimated one in four devices and could leave recovery phrases with insufficient randomness, or entropy, likely playing on fears related to the recent Coldcard exploit that cost users over $130 million in Bitcoin.
Market Context
Bitcoin
BTC
$78,270
-0.63% (24H)
Market Cap
$1.57T
24H Volume
$30.0B
24H High
$79,739
Article Intelligence
Key Entities
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
