Trezor Warns of Phishing Emails After Third-Party Breach
Sep 10, 2026
Trezor says a third-party email provider was breached, letting scammers send phishing emails from a legitimate domain. Here's what the company is telling users to watch out for.
What Happened
Trezor, one of the biggest names in hardware wallets, just confirmed something a little unsettling. A third-party email provider they use got breached, and the attackers used that access to blast out phishing emails that actually came from a legitimate domain tied to the company.
The fake message was titled something like "Critical Security Alert: STM32 Entropy Vulnerability", which sounds technical enough to trick even careful users into clicking.
Why It Matters
Trezor has been clear that this wasn't a hack of their wallets or firmware. It's a classic supply-chain problem, where trusting the wrong vendor becomes an opening for scammers. The company says it's still investigating and is telling everyone not to click any links in emails claiming to be urgent security alerts.
If you use a hardware wallet, this is a good reminder that your seed phrase should never be entered anywhere online, no matter how official the email looks. When in doubt, go straight to the source instead of clicking through.