Trezor Warns Users of Phishing Campaign Exploiting Legitimate Email Infrastructure
Hardware wallet manufacturer Trezor alerted users on Wednesday, September 9, 2026, about a sophisticated phishing campaign that exploited the company’s third-party email provider to distribute a fraudulent security notice. While Trezor wallets themselves remained unaffected, the attack targeted something more difficult to secure than software: user trust in communications from verified senders.
Fabricated Vulnerability Sent from Verified Domain
The phishing email carried the subject line: “Critical Security Alert: STM32 Entropy Vulnerability.” The message claimed Trezor engineers had discovered a design defect in STM32 chips used in the company’s products, warning that one in four devices could become compromised and that recovery phrases might lack sufficient randomness or entropy. This language closely mirrored issues described in the recent Coldcard firmware exploit.
According to a report by Decrypt, Trezor identified the message as fraudulent and urged recipients not to click any links.
Email Passed All Authentication Checks
What made the campaign particularly effective was its delivery mechanism. One recipient reported the email originated from [email protected], traversed the Sendinblue campaign infrastructure, and successfully passed DKIM, SPF, and DMARC authentication checks—technical validations typically used to verify sender legitimacy.
Trezor confirmed it had disabled the domain used for the malicious alerts and launched an investigation into how threat actors accessed its legitimate sending infrastructure. The company issued its public warning shortly after 4:30 PM Eastern Time on September 9, just hours after users began reporting the suspicious emails.
Broader Pattern Suggests Compromised Marketing Provider
The breach may extend beyond Trezor. Nick Neuman, co-founder and CEO of Casa, indicated a similar trend appears to be affecting BitBox users, suggesting a common marketing email provider may have been compromised.
This highlights a systemic vulnerability: wallet manufacturers can strengthen device security, but their brand reputation remains exposed through third-party dependencies—including email service providers, shipping partners, and payment processors—that they do not fully control.
Distinction Between Data Breaches and Device Exploits
Security analysts emphasize the critical difference between data breaches and device exploits. A previous Cryptopolitan report revealed phishing attempts against Ledger users have expanded into physical mail, yet these incidents compromise identity and contact information rather than directly exposing financial assets.
The 2026 hardware wallet security landscape illustrates this distinction clearly:
- SafePal disclosed an authorization error in an order tracking plugin exposed data for approximately 39,798 customers, confirming seed phrases, private keys, and wallet credentials were not compromised.
- Trezor’s ShipMonk breach ultimately affected 80,689 customers after the company discovered legacy U.S. order records from 2019–2021 were also exposed.
- Ledger’s Global-e incident in January exposed customer order details and contact information, though the exact number of affected users was not disclosed.
In an August comparison, Memeburn correctly categorized Ledger, Trezor, and SafePal under “data breaches” while identifying Coldcard as a “device exploit.” The 13,689 figure Memeburn cited for Trezor predates the company’s September 4 update.
Coldcard Exploit Represents Distinct Threat Category
Coldcard stands apart from the data exposure incidents. According to Galaxy Research on August 14, the firmware flaw resulted in 190 confirmed victims, over 86,000 affected addresses, and at least $112.7 million (1,778.84 BTC) in stolen assets. Other estimates place potential losses near $130 million.
Leaked Purchase Data Fuels Industrialized Phishing
The danger of exposed shipping records lies in their utility for targeted attacks. Chainalysis estimated crypto scams and fraud stole $17 billion in 2025, with impersonation scams growing more than 1,400% year over year. The firm also found scams linked to AI vendors generated 4.5 times more revenue per operation than those without such connections.
A hardware wallet purchase record—combining name, email, phone number, home address, and confirmation of crypto security device ownership—provides criminals with the context to craft highly convincing emails, calls, letters, or even physical approaches.
Security Perimeter Extends Beyond the Device
The lesson from Trezor’s latest incident is not that hardware wallets failed. It is that the security perimeter now encompasses the entire ecosystem surrounding them, and attackers increasingly need only a single trusted-looking message to breach defenses.

