Roobet Banner
BTC $77,219.00 (-1.79%)
ETH $2,441.94 (-2.01%)
BNB $708.06 (-4.23%)
XRP $1.36 (-4.39%)
SOL $99.70 (-3.35%)
TRX $0.34 (+0.16%)
ZEC $1,169.61 (-8.24%)
HYPE $80.78 (-5.05%)
DOGE $0.08 (-5.93%)
RAIN $0.02 (-2.54%)
XMR $506.54 (+0.91%)
LINK $11.62 (-3.16%)
LEO $9.20 (+0.18%)
ADA $0.21 (-3.03%)
XLM $0.18 (-3.72%)
BCH $225.91 (-12.34%)
LTC $52.22 (-3.50%)
CC $0.10 (-2.97%)
GRAM $1.35 (-2.17%)
UNI $6.01 (-8.07%)

Trezor's Own Domain Sends Phishing Emails After Email Provider Hack

Share on X icon · Published 8 घंटे पहले on September 10, 2026 · Nikolas Sargeant

Trezor warns that hackers used its official domain to send phishing emails after breaching a third-party provider and urges users not to click the links.

Trezor's Own Domain Sends Phishing Emails After Email Provider Hack

TL;DR

  • Trezor says attackers breached a third-party email provider and sent phishing messages from its official domain. 

  • The fraudulent alert instructed users to update their wallets because of a supposed vulnerability. Trezor has taken the domain offline and is investigating the breach.

Hardware wallet manufacturer Trezor has disclosed a breach involving a third-party email provider that allowed attackers to send phishing messages from the company’s official domain.

Trezor warned customers Wednesday about an email titled “Critical Security Alert: STM32 Entropy Vulnerability,” stressing that the message was fraudulent and urging recipients not to click any links.

The company has since taken the affected domain offline and opened an investigation into the incident, including how the attackers gained the ability to distribute messages using its legitimate domain.

Phishing Email Urged Users to Update Their Wallets

The malicious email claimed that a critical vulnerability could affect newer Trezor devices and instructed customers to update their hardware wallets.

Crypto commentator Marcello Paz shared screenshots of the message, showing that it contained official-looking domain credentials and signatures. Those features made the campaign potentially more convincing than conventional phishing attacks, which typically rely on misspelled or imitation email addresses.

The attack poses a significant risk because hardware wallet phishing campaigns often attempt to steal seed phrases or persuade users to install malicious software. Trezor has repeatedly emphasized that customers should never disclose their wallet recovery seeds.

Swiss Bitcoin hardware wallet company BitBox reported a similar phishing email circulating under its name on the same day.

The latest security issue comes shortly after Trezor disclosed a substantial breach at ShipMonk, one of its shipping providers.

Trezor initially said the incident exposed names, cities, and email addresses belonging to approximately 13,700 customers. The company later revealed that another 67,000 customers in the United States had also been affected.

Although those incidents did not directly compromise hardware wallets, leaked contact information can help criminals create more targeted and believable phishing campaigns.

Hardware Wallet Companies Face Persistent Threats

Trezor has also faced scrutiny over hardware security. In June, Ledger’s Donjon research team disclosed a vulnerability in the TROPIC01 chip used in the Trezor Safe 7.

Researchers demonstrated a laboratory-based laser attack capable of bypassing the chip’s firmware verification system. Trezor said no customer funds were at risk.

Hardware wallet users have long been targets of social-engineering attacks. A 2020 Ledger breach exposed information belonging to more than 270,000 customers, including names, emails, phone numbers, and some home addresses. Some affected customers continued to receive fraudulent calls and physical letters years later.

 

Bitcoin Falls to $77,000 as Hot US Inflation Data Lifts Yields
Next article Bitcoin Falls to $77,000 as Hot US Inflation Data Lifts Yields
Nikolas Sargeant
Nikolas Sargeant Editor-in-Chief

Nik is a content and public relations specialist with an ever-growing interest in Crypto. He has been published on several leading Crypto and blockchain based news sites. He is currently based in Spain, but hails from the Pacific Northwest in the US.