Trezor's email system hijacked to send fake 'security alert' phishing to customers
Criminals used a breached third-party email provider to send phishing from a real Trezor address, weeks after a separate shipping-partner breach ballooned to 81,000 customers.

Key points
- Trezor confirmed on Wednesday that its third-party email provider was breached and used to send phishing emails from its real help@trezor.io address.
- The fake emails carried the subject "Critical Security Alert: STM32 Entropy Vulnerability" and tried to trick wallet owners into exposing their recovery seeds.
- A separate breach at shipping partner ShipMonk, first disclosed in August, now affects 81,000 Trezor customers, up from an initial 14,000.
- The ShipMonk intrusion is linked to a critical SQL injection zero-day in Metabase, with extortion demands sent by the ShinyHunters gang.
- This is the third third-party breach hitting Trezor customers in under two years, after a support-portal incident exposed 66,000 users in January 2024.
Cryptocurrency hardware wallet maker Trezor told customers on Wednesday that criminals broke into its outside email provider and used the access to send phishing emails from Trezor's real address.
A hardware wallet is a small physical device, roughly the size of a USB stick, that stores the secret keys to someone's cryptocurrency offline. If an attacker gets the recovery phrase, known as a seed, they can drain the wallet from anywhere in the world.
That is exactly what these phishing emails were fishing for.
What did the fake emails say?
The emails arrived from help@trezor.io, a genuine Trezor address, with the subject line "Critical Security Alert: STM32 Entropy Vulnerability". They claimed a flaw in the STM32 microcontroller chip inside Trezor devices could let attackers guess the wallet's seed by brute force, meaning trying huge numbers of combinations until one works.
None of that is true. It was bait to push worried customers into clicking a link and handing over their recovery phrase.
"Our third-party e-mail provider has been breached," Trezor said in its warning. "Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link."
The company said it has taken down the domain used in the scam and is investigating how the attackers reached its legitimate sending infrastructure. It has not named the email provider.
How does this connect to the ShipMonk breach?
Separately, Trezor disclosed a much bigger data breach in August involving ShipMonk, the logistics company that ships its wallets. On Friday, Trezor updated the number of affected customers from roughly 14,000 to 81,000 after a follow-up review found another 67,000 U.S. buyers had been caught up in it.
The stolen records include full names, shipping addresses, email addresses and phone numbers for people who received orders between 10 May and 8 August 2026. Customers in Brazil, Colombia, Italy, Portugal, Sweden and the United Kingdom were also affected.
According to breach notification emails first reported by BleepingComputer, the attackers got into ShipMonk by exploiting a flaw in Metabase, an open-source analytics tool. Metabase confirmed in early August that criminals were using a critical SQL injection zero-day to take administrator control of customer instances and steal data. A zero-day is a software bug the maker did not know about before attackers started using it.
ShipMonk was then hit with extortion demands from ShinyHunters, a group known for stealing data and threatening to publish it.
Is this the first time Trezor customers' data has leaked?
No. In January 2024, Trezor disclosed that a third-party support ticketing portal had been breached, exposing names, usernames and email addresses for about 66,000 users. Between that, the ShipMonk incident and now the email provider hijack, Trezor customers have been exposed three times through outside suppliers in less than two years.
| Incident | Disclosed | People affected | Data or method |
|---|---|---|---|
| Support portal breach | January 2024 | ~66,000 | Names, usernames, emails |
| ShipMonk shipping data | August 2026 (updated) | 81,000 | Names, addresses, phones, emails |
| Email provider hijack | November 2026 | Not disclosed | Phishing from real Trezor address |
What should Trezor customers do now?
Treat any email claiming a Trezor security flaw with deep suspicion, even if it comes from a legitimate-looking address. Never enter your recovery seed into a website, an app, or an email form. Trezor will never ask for it.
Customers whose shipping details were exposed in the ShipMonk breach should also expect targeted phishing by post, phone and SMS, because attackers now know their home address alongside the fact that they own a crypto wallet. That combination is unusually dangerous, and worth flagging to anyone in the household who might open the door or the mail.



