Trezor has warned customers that hackers who breached a third-party email provider are using stolen access to send phishing messages designed to obtain cryptocurrency wallet recovery seeds.
The fraudulent emails appear to come from help@trezor.io and are headed “Critical Security Alert: STM32 Entropy Vulnerability”. They falsely claim that a vulnerability in the STM32 microcontrollers used in Trezor’s hardware wallets could leave users’ recovery seeds exposed to brute-force attacks.
Trezor said the message was not genuine and urged recipients not to click on any links or follow its instructions.
“Our third-party e-mail provider has been breached,” the company said. “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”
The company said it had taken down the domain involved in the campaign and was investigating how the attackers gained access to its legitimate domain and email infrastructure.
Trezor investigates latest security incident
The warning comes after a separate breach at ShipMonk, Trezor’s shipping and logistics provider, which exposed customer order information including names, delivery addresses, email addresses and telephone numbers.
Trezor initially said the ShipMonk incident affected almost 14,000 customers. A subsequent investigation identified a further 67,000 affected customers in the United States, taking the total to about 81,000.
The earlier breach also involved customers in Brazil, Colombia, Italy, Portugal, Sweden and the UK who received orders between May 10 and August 8, 2026. Notifications linked the incident to an exploited vulnerability in Metabase, an analytics platform.
Trezor has also disclosed a 2024 breach involving its customer support ticketing system, in which attackers accessed the names, usernames and email addresses of roughly 66,000 users.
The company has not said how many customers were targeted by the latest phishing emails. It is continuing to investigate the breach at its email provider.
