Trezor Investigates Email Provider Breach After Phishing Mimics STM32 ‘Entropy’ Alert

Trezor says a third-party email provider was breached, sending a fake “STM32 Entropy” alert to users. Similar messages hit BitBox, headers passed DKIM/SPF. Here’s what happened and why it matters.

Bitcoin
Cryptocurrency
Regulations
Economy
Because Bitcoin
Because Bitcoin

Because Bitcoin

September 10, 2026

Trezor is probing a breach at a third-party email provider after attackers blasted customers with a convincing phishing message dressed up as a critical security notice. The campaign leaned on a subject line—“Critical Security Alert: STM32 Entropy Vulnerability”—and appeared to originate from legitimate trezor.io infrastructure, prompting some users to click before the company could respond.

The lure asserted that Trezor engineers had uncovered a hardware-level flaw in STM32 microcontrollers used in its devices. It claimed the issue affected roughly one in four units and could compromise the randomness of recovery phrases, echoing recent anxiety around a Coldcard-related exploit that resulted in losses exceeding $130 million in Bitcoin. Trezor later labeled the email fraudulent on X, advising users not to follow any links, and said it had disabled the domain used in the attack while investigating how access to its legitimate-sounding mail pathways was achieved. The company’s public warning landed shortly after 4:30 p.m. Eastern, hours after early reports surfaced.

What made this wave effective was not just the subject matter but the trust signals. One recipient shared headers showing “From: Trezor Security <help@trezor.io>” with a return-path of “noreply@mailing.trezor.io,” routed through a Sendinblue campaign, with DKIM, SPF, and DMARC all passing. Those markers typically reassure users and filters; here they likely amplified the credibility of a false alarm.

Reports suggest the incident may extend beyond a single brand. Casa cofounder Nick Neuman said he heard of identical emails reaching BitBox users and posited a compromised marketing email platform. Casa’s Jameson Lopp similarly cautioned that threat actors may have gained access to the providers used by both Trezor and BitBox, noting the messages didn’t look spoofed and that no such advisory had actually been issued.

This comes on the heels of a tense summer for hardware wallet security communications. In August, Trezor and Foundation warned of phishing attempts piggybacking on disclosures about vulnerabilities affecting Coldcard devices. That same month, Trezor reported that a breach at logistics partner ShipMonk exposed data for 80,689 individuals—including names, email addresses, phone numbers, and shipping addresses—and warned that the leak could be repurposed for more tailored phishing.

The common thread isn’t a novel exploit against wallets; it’s a classic supply-chain failure at the communications layer. Email authentication (DKIM/SPF/DMARC) confirms origin alignment, not intent. When adversaries secure access to the sender’s marketing stack, the very safeguards designed to block spoofing become the scaffolding for believable lies. Pair that with a technically plausible pretext—entropy, RNG, STM32—and you get high click-through on malicious links without needing to break hardware.

For hardware wallet makers, the cost is trust. Security notices should be the rarest, most carefully handled messages a brand sends. Treat them like code: sign them, publish them first on a canonical status page, and never require link-clicks to remediate. Segregate high-risk communications from bulk marketing infrastructure; assume that CRM credentials, API keys, and mailing subdomains are attractive targets. For users, the durable rule holds: updates happen inside the device’s software, never via an email link—verify advisories through the official app or a known, bookmarked domain.

A feasible uplift path looks like this: - Use cryptographically signed advisories with verifiable fingerprints surfaced in-app. - Enforce strict separation of duties and domains for marketing versus security notifications. - Rotate and scope email provider keys; monitor for anomalous campaign creation. - Precommit to a “no links in security emails” policy so deviations are obvious.

Attackers will continue to exploit moments of industry anxiety—like the Coldcard losses—to compel action. That dynamic won’t change. What can change is the communication trust model: fewer external dependencies, stronger in-product verification, and user expectations calibrated to ignore urgency plays arriving by email.