Trezor users woke on September 9 to an email warning of a critical flaw in their hardware wallets. The email was fake. Attackers broke into one of the company's third-party email providers and blasted a phishing message to Trezor's newsletter list. The devices stayed untouched. What got hit, again, was the contact data around them.
Trezor confirmed the provider breach and told users to click nothing inside the message. The mail compromise exposed no private keys or recovery phrases, and the company says the wallets remain secure.
The fake alert claimed one in four devices were at risk
The phishing email carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability." It claimed a flaw in the STM32 microcontroller had weakened recovery phrase entropy on roughly one in four devices, then steered readers toward links to "check" their wallet. Trezor's reply was blunt. "Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt," the company wrote.
The framing was deliberate. A holder who believes their seed is suddenly weak will type it into whatever page promises to verify it. Pages tied to the campaign asked for extended public key data, which can reveal a user's addresses and balances.
Two vendor breaches in a month, zero stolen keys
This is the second time in about a month that a company Trezor depends on has leaked its customers. In August the fulfillment vendor ShipMonk disclosed a breach exposing names, emails, phone numbers and shipping addresses for more than 80,000 Trezor customers, a count that climbed once it absorbed older US records from 2019 to 2021. Trezor did not name the email provider hit on September 9, and outside researchers pointed to markers of an email-marketing platform rather than a core system.
Neither breach reached a signing key. Both handed attackers what a phishing run needs most, a verified list of real owners on a channel they already trust. Trezor's record on warning people after an incident has drawn scrutiny before, and the data already loose gives the next wave a head start.
Self-custody moves the target to the inbox
Hardware wallets exist so a private key never leaves the device, and on that narrow test Trezor held. The lesson this month is that the key is often not where the money disappears. Liquid Network lost close to 4,000 bitcoin in early September with no stolen key, through a software bug rather than a compromised signer. For a holder, the soft spot is the inbox and the reflex to click.
A real firmware warning shows up on the device screen. It never lands in your inbox asking for a seed. Anyone unsure where a recovery phrase belongs can review the gap between cold and hot wallet storage. Trezor says it is containing the breach and urges users to confirm notices through official channels. Anyone who typed a phrase into a linked page should move funds now.