Trezor said on September 9, 2026, that a breach at a third-party email provider enabled phishing emails to be sent from its legitimate mailing domain. The hardware-wallet maker warned recipients that messages carrying the subject line “Critical Security Alert: STM32 Entropy Vulnerability” were fraudulent, said it had removed the linked domain, and was investigating how access to its legitimate domain was obtained.
Trezor Confirms Third-Party Email Provider Breach
Trezor said at 21:43 UTC on the Trezor Forum that a third-party email provider had been breached rather than Trezor itself.
The company said the phishing emails appeared to come through its legitimate mailing domain, mailing.trezor.io.
Trezor said emails titled “Critical Security Alert: STM32 Entropy Vulnerability” were fraudulent, that the linked domain had been taken down, and that it was investigating access to the legitimate domain.
Phishing Attachment Targeted Wallet Seed Phrases
Before Trezor’s statement, a forum user reported at 21:17 UTC on September 9 that the emails had arrived through mailing.trezor.io. The user said an attached HTML file attempted to capture wallet seed phrases and transmit them to a Telegram bot, according to the same forum thread.
Although Trezor’s subsequent notice independently confirmed that the specified email campaign was phishing, it did not describe the attachment’s alleged Telegram-bot mechanism. That detail remains part of a user report, rather than a technical assessment published by Trezor.
Trezor’s removal of the linked domain addresses the destination named in its warning, while its investigation remains directed at the access that allowed phishing mail to use the legitimate domain.
Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.
