Trezor warns of phishing from its real domain after email provider breach

Trezor warns of phishing from its real domain after email provider breach

The emails arrive from the company's legitimate domain and pressure users to urgently update their wallet due to a fictitious vulnerability.

Sep 10, 2026

Hardware wallet maker Trezor reported phishing emails disguised as urgent security notices. The incident is linked to the compromise of a third-party email provider through which the company sends mail to customers. Trezor announced the issue on September 9, 2026.

What is known about the Trezor phishing campaign

Trezor stated that an email titled "Critical Security Alert: STM32 Entropy Vulnerability" did not come from the company. Users were asked not to click any links.

The company confirmed that its email provider had been compromised, which allowed the attackers to send messages from Trezor's official domain. The domain used in the mailing has since been taken down. The investigation continues — including how the scammers managed to use the manufacturer's own infrastructure.

According to recipients, the email pushed them to update the firmware due to a "critical" vulnerability that supposedly affects newer devices.

A wave of incidents around Trezor and hardware wallets

The warning comes amid a series of incidents in the hardware wallet sector over the past few months.

Among earlier cases, in June 2026 Ledger's security team Donjon disclosed a vulnerability in the TROPIC01 chip used in the Trezor Safe 7. It was a lab-based laser attack that bypassed the chip's firmware verification. Trezor stressed that user funds were not at risk.

Customer data leaks remain one of the sector's key problems. Back in 2020, after a Ledger breach, the names, addresses, and phone numbers of more than 270K customers were leaked online. Years later, victims still report scam calls and physical letters trying to trick them into revealing their seed phrase.

#Hack
Trezor warns of phishing from its real domain after email provider breach