Trezor Warns of Phishing Attacks After Third-Party Email Provider Breach ("STM32 Entropy Vulnerability" Lure)
Trezor Warns of Phishing Attacks After Third-Party Email (TL-2026-2432), also tracked as STM32 Entropy Vulnerability Phishing Campaign, is a medium-severity phishing campaign, first published 2026-09-10. It has no confirmed attribution, affects SatoshiLabs (Trezor) Trezor customer email communications sent via, maps to 10 MITRE ATT&CK techniques (T1078.004, T1199, T1204.001), and is covered by 9 detection rules and 11 indicators of compromise.
Key facts for TL-2026-2432
- Threat ID
- TL-2026-2432
- Also known as
- STM32 Entropy Vulnerability Phishing Campaign
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-10
- Last reviewed
- 2026-09-10
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, finance
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 11
Trezor's third-party email provider was breached, letting attackers send a phishing email from the legitimate help@trezor.io address claiming a fake STM32 microcontroller entropy flaw exposed seed phrases to brute-forcing. The email passed SPF/DKIM/DMARC checks; BitBox reported a near-identical campaign the same day, pointing to a shared compromised marketing/email provider.
How Trezor Warns of Phishing Attacks After Third-Party Email works
On September 10, 2026, hardware wallet manufacturer Trezor (operated by SatoshiLabs) warned customers that a third-party email provider it uses had been breached, and the access was abused to send a phishing email from Trezor's legitimate help@trezor.io address. The message, titled "Critical Security Alert: STM32 Entropy Vulnerability," falsely claimed that Trezor engineers had discovered a critical hardware-level flaw in the STM32 microcontrollers used in roughly one in four Trezor devices, alleging that recovery seed phrases could be exposed to brute-force cracking due to insufficient entropy. The email urged recipients to click a link to "update" their device, a lure engineered to harvest seed phrases or otherwise compromise victims' cryptocurrency wallets.
Because the email was sent through Trezor's own breached third-party sending infrastructure rather than a spoofed look-alike domain, it passed SPF, DKIM, and DMARC authentication checks, making it significantly more convincing than typical phishing lures that rely on cosmetically similar domains. Trezor stated the email "is not coming from us, and it's a phishing attempt," instructed customers not to click any link, took down the malicious landing-page domain, and opened an investigation into how the attackers gained the ability to send mail as its official domain.
The same day, Swiss hardware wallet maker BitBox reported a near-identical phishing campaign impersonating its own brand, stating its "newsletter provider" was very likely compromised. Security researchers -- including Casa co-founder Nick Neuman and independent researcher Jameson Lopp -- publicly assessed that a single shared third-party email/marketing provider used by multiple cryptocurrency companies had likely been compromised and abused to launch coordinated phishing against both vendors' customer bases simultaneously. The specific provider has not been publicly confirmed by either Trezor or BitBox as of this writing.
The incident is the latest in a string of third-party vendor compromises reaching Trezor's customers: in January 2024 a breach of Trezor's third-party support ticketing portal exposed roughly 66,000 (later revised to 80,689) customers' names and emails and was likewise followed by phishing attempts, and in August-September 2026 a breach at fulfillment partner ShipMonk (via a critical SQL-injection flaw, CVE-2026-72898, in ShipMonk's Metabase deployment) exposed shipping and contact data for roughly 81,000 Trezor customers. While unrelated in root cause, these incidents collectively illustrate a recurring risk pattern: Trezor's own hardware and firmware are not implicated, but repeated breaches of the third-party vendors that hold or transmit Trezor customer contact data create a steady supply of credible pretexts and target lists for social-engineering campaigns against cold-storage wallet holders.
MITRE ATT&CK techniques used in TL-2026-2432
Defense Evasion
T1078.004 Valid Accounts: Cloud Accounts; T1684.001 Impersonation
Initial Access
T1199 Trusted Relationship; T1566.002 Phishing: Spearphishing Link
Execution
T1204.001 User Execution: Malicious Link
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1584.006 Compromise Infrastructure: Web Services; T1586.002 Compromise Accounts: Email Accounts
Reconnaissance
T1589.002 Gather Victim Identity Information: Email Addresses
Impact
Affected products and versions in Trezor Warns of Phishing Attacks After Third-Party Email
- SatoshiLabs (Trezor) — Trezor customer email communications sent via third-party email provider (help@trezor.io)
Vulnerable versions: Third-party email/marketing provider integration; exact vendor unconfirmed as of 2026-09-10
Fixed in: Malicious landing-page domain taken down by Trezor; provider-side remediation not yet publicly confirmed - BitBox (Shift Crypto) — BitBox customer newsletter/email communications
Vulnerable versions: Suspected shared third-party newsletter provider; exact vendor unconfirmed
Fixed in: Not publicly confirmed
Remediation for Trezor Warns of Phishing Attacks After Third-Party Email
Immediate actions
- Do not click links in the 'Critical Security Alert: STM32 Entropy Vulnerability' email or any unsolicited Trezor/BitBox security alert; verify any advisory via the vendor's official app or website, never via an emailed link
- Report the phishing email to Trezor or BitBox support channels and delete it without interacting
- Never enter a seed phrase, recovery phrase, or passphrase into any web page reached via an emailed link
Workarounds
- Treat any unsolicited 'critical vulnerability' email about a hardware wallet as phishing by default; confirm real advisories only via the vendor's official app, verified social media, or its own blog domain directly
Longer-term hardening
- Vendors: audit and rotate credentials for all third-party email/marketing/newsletter platforms and enforce MFA on those accounts
- Vendors: monitor SPF/DKIM/DMARC-passing mail sent through third-party ESPs for anomalous campaign activity, not just spoofed-domain mail
- Vendors: minimize customer PII (email addresses) held by or shared with third-party marketing and fulfillment providers, and contractually enforce data deletion after a partnership ends
Timeline of Trezor Warns of Phishing Attacks After Third-Party Email
- Trezor discloses unauthorized access to its third-party support ticketing portal, later found to affect roughly 66,000 (revised to 80,689 in March 2024) customers' names and emails; the exposure was followed by phishing attempts against affected users.
- Trezor's fulfillment/logistics partner ShipMonk notifies Trezor of unauthorized access to its systems, exploiting a critical SQL-injection flaw (CVE-2026-72898, CVSS 10.0) in ShipMonk's Metabase analytics deployment.
- Trezor publicly discloses the ShipMonk breach, initially affecting close to 14,000 customers' shipping addresses, names, emails, and phone numbers.
- ShipMonk informs Trezor that the breach also exposed historical order data from a prior partnership period (November 2019 - August 2021) that should have been deleted.
- Trezor updates its disclosure: the ShipMonk breach total reaches roughly 81,000 customers (about 67,000 additional US customers) after ShipMonk failed to delete retained data per its contract with Trezor.
- Security researchers (Casa's Nick Neuman, independent researcher Jameson Lopp) and multiple outlets report the Trezor and BitBox phishing emails passed SPF/DKIM/DMARC checks and were likely sent via a shared, compromised third-party marketing/email provider used by several cryptocurrency companies.
- Trezor takes down the malicious domain linked from the phishing email and opens an investigation into how attackers gained the ability to send mail as its official domain.
- Trezor warns customers that its third-party email provider was breached and used to send a phishing email titled 'Critical Security Alert: STM32 Entropy Vulnerability' from the legitimate help@trezor.io address, falsely claiming an STM32 microcontroller entropy flaw could expose seed phrases to brute-force attack.
- BitBox's preliminary review concludes it is very likely that its newsletter/email provider was compromised.
- BitBox posts an early-morning warning on X that a phishing email impersonating BitBox is circulating and opens an investigation.
Sources cited for Trezor Warns of Phishing Attacks After Third-Party Email
- Trezor warns users of email provider breach, phishing attacks
- Trezor says third-party security breach led to phishing emails from legitimate domain
- Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider
- Fake Security Emails Target Trezor and BitBox Users
- Multiple hardware crypto wallet providers warn of phishing emails after third-party incident
- Trezor data breach impact now reaches 81,000 customers
- Explained: The Trezor/ShipMonk Breach (August 2026)
- Trezor support site breach exposes personal data of 66,000 customers
- Trezor security alert: Stay vigilant against a potential phishing attack
- Trezor (@Trezor) official statement on X
More in phishing
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration
- Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters
- Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)
Detection coverage for TL-2026-2432
As of 2026-09-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2432 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.