Trezor's Bitcoin (BTC) Wallet Users Hit by Phishing From Breached Email Domain
Trezor confirms a third-party email breach let attackers send phishing from its own domain, targeting Bitcoin wallet users weeks after the ShipMonk breach…
AI SummaryAI
- Trezor confirmed September 9 that a third-party email provider breach enabled phishing from its legitimate domain
- Phishing emails cited a fake “STM32 Entropy Vulnerability” to trick users into revealing wallet backups
- The same campaign hit BitBox, CoinTracking, Peach Bitcoin, and Blocktrainer via the shared email platform
- Messages routed through mailing.trezor.io and passed SPF, DKIM, and DMARC authentication checks
Phishing Sent From Trezor’s Own Domain
Hardware wallet maker Trezor confirmed on September 9 that a third-party email provider it uses was breached, allowing attackers to send phishing messages that appeared to come from the company’s own legitimate domain. The fraudulent emails carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and warned subscribers of a critical randomness flaw supposedly affecting the STM32 microcontrollers inside newer Trezor devices. The messages pressed recipients to run an urgent security check — the lure designed to walk them into entering their wallet backup phrase on an attacker-controlled page. Trezor’s official statement, posted on X, told users the alert was not from the company, urged them not to click any link, and confirmed the affected domain had been taken down while an investigation into how the attackers obtained send access continues. As of September 10, the company has not disclosed the number of recipients, the identity of the email vendor, or any confirmed user losses.
posted on Xhttps://x.com/Trezor/status/2097786518110609620?s=20
Same Campaign Hits BitBox and CoinTracking
The blast radius extends well beyond Trezor. The same compromised email platform also serves BitBox, CoinTracking, Peach Bitcoin, and Blocktrainer, and all four issued warnings to their own customers. Screenshots circulating show the campaign was tailored per brand: CoinTracking recipients were fed a fabricated breach notice, while BitBox users were told of a microcontroller entropy bug. What makes this incident technically serious is that the messages were not lookalike spoofs — users who published full email headers on Trezor’s official forum showed the mail routing through mailing.trezor.io, and several reported that it passed SPF, DKIM, and DMARC authentication checks. Independent analysis also found the malicious links initially redirected through Trezor’s own email-tracking subdomain, meaning even a cautious recipient hovering over links saw trusted infrastructure. Security researchers have pointed to Brevo as the affected platform, but Trezor has not officially named the vendor, so that identification remains unconfirmed.
Screenshots circulatinghttps://x.com/Trezor/status/2097948765357236502?s=20
ShipMonk Breach Exposed 80,000 Customers
The email compromise lands weeks after a separate supplier failure. On August 13, Trezor disclosed that its shipping partner ShipMonk had been breached, initially exposing full contact details for 11,742 customers — names, emails, phone numbers, and shipping addresses — with another 1,947 partially affected, tied to orders placed between May and August. Early this month the company widened the disclosure: ShipMonk had retained old order data it was contractually required to delete under a 90-day policy, adding roughly 67,000 US customers with orders reaching back to November 2019. The combined exposure now exceeds 80,000 customers, though Trezor has published no unified figure. The company warned at the time that the leaked data could fuel precisely the kind of targeted phishing, phone scams, and physical social-engineering attacks now unfolding. No public evidence links the ShipMonk leak to the email breach, and it is not confirmed whether the mailing list came from previously leaked records. Trezor’s support-ticket portal was also breached in January 2024, placing about 66,000 users at phishing risk. Readers tracking the market in real time can follow live spot and futures prices on Bybit.
Cold Storage Does Not Remove Supply-Chain Risk
Our reading of the incident record is that this is a single thematic arc: attackers are not trying to crack the hardware, they are attacking everything around it. Unlike on-chain threats such as MEV extraction, omnichain bridge exploits, or funds laundered through a crypto mixer, no drained transactions are needed here — no confirmed on-chain losses tied to this campaign have surfaced yet, and the primary evidence remains Trezor’s own incident statements. The company’s remediation guidance is unchanged: never enter a wallet backup on any website, and treat any request for a seed phrase, PIN, or verification code as fraud, regardless of how authentic the sender looks.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


