Trezor Warns of Phishing Attacks After Third-Party Email Provider Breach ("STM32 Entropy Vulnerability" Lure)

Trezor Warns of Phishing Attacks After Third-Party Email (TL-2026-2432), also tracked as STM32 Entropy Vulnerability Phishing Campaign, is a medium-severity phishing campaign, first published 2026-09-10. It has no confirmed attribution, affects SatoshiLabs (Trezor) Trezor customer email communications sent via, maps to 10 MITRE ATT&CK techniques (T1078.004, T1199, T1204.001), and is covered by 9 detection rules and 11 indicators of compromise.

Key facts for TL-2026-2432

Threat ID
TL-2026-2432
Also known as
STM32 Entropy Vulnerability Phishing Campaign
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-09-10
Last reviewed
2026-09-10
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
cryptocurrency, finance
Target regions
Global
Detection rules
9
Indicators of compromise
11

Trezor's third-party email provider was breached, letting attackers send a phishing email from the legitimate help@trezor.io address claiming a fake STM32 microcontroller entropy flaw exposed seed phrases to brute-forcing. The email passed SPF/DKIM/DMARC checks; BitBox reported a near-identical campaign the same day, pointing to a shared compromised marketing/email provider.

How Trezor Warns of Phishing Attacks After Third-Party Email works

On September 10, 2026, hardware wallet manufacturer Trezor (operated by SatoshiLabs) warned customers that a third-party email provider it uses had been breached, and the access was abused to send a phishing email from Trezor's legitimate help@trezor.io address. The message, titled "Critical Security Alert: STM32 Entropy Vulnerability," falsely claimed that Trezor engineers had discovered a critical hardware-level flaw in the STM32 microcontrollers used in roughly one in four Trezor devices, alleging that recovery seed phrases could be exposed to brute-force cracking due to insufficient entropy. The email urged recipients to click a link to "update" their device, a lure engineered to harvest seed phrases or otherwise compromise victims' cryptocurrency wallets.

Because the email was sent through Trezor's own breached third-party sending infrastructure rather than a spoofed look-alike domain, it passed SPF, DKIM, and DMARC authentication checks, making it significantly more convincing than typical phishing lures that rely on cosmetically similar domains. Trezor stated the email "is not coming from us, and it's a phishing attempt," instructed customers not to click any link, took down the malicious landing-page domain, and opened an investigation into how the attackers gained the ability to send mail as its official domain.

The same day, Swiss hardware wallet maker BitBox reported a near-identical phishing campaign impersonating its own brand, stating its "newsletter provider" was very likely compromised. Security researchers -- including Casa co-founder Nick Neuman and independent researcher Jameson Lopp -- publicly assessed that a single shared third-party email/marketing provider used by multiple cryptocurrency companies had likely been compromised and abused to launch coordinated phishing against both vendors' customer bases simultaneously. The specific provider has not been publicly confirmed by either Trezor or BitBox as of this writing.

The incident is the latest in a string of third-party vendor compromises reaching Trezor's customers: in January 2024 a breach of Trezor's third-party support ticketing portal exposed roughly 66,000 (later revised to 80,689) customers' names and emails and was likewise followed by phishing attempts, and in August-September 2026 a breach at fulfillment partner ShipMonk (via a critical SQL-injection flaw, CVE-2026-72898, in ShipMonk's Metabase deployment) exposed shipping and contact data for roughly 81,000 Trezor customers. While unrelated in root cause, these incidents collectively illustrate a recurring risk pattern: Trezor's own hardware and firmware are not implicated, but repeated breaches of the third-party vendors that hold or transmit Trezor customer contact data create a steady supply of credible pretexts and target lists for social-engineering campaigns against cold-storage wallet holders.

MITRE ATT&CK techniques used in TL-2026-2432

Defense Evasion

T1078.004 Valid Accounts: Cloud Accounts; T1684.001 Impersonation

Initial Access

T1199 Trusted Relationship; T1566.002 Phishing: Spearphishing Link

Execution

T1204.001 User Execution: Malicious Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1584.006 Compromise Infrastructure: Web Services; T1586.002 Compromise Accounts: Email Accounts

Reconnaissance

T1589.002 Gather Victim Identity Information: Email Addresses

Impact

T1657 Financial Theft

Affected products and versions in Trezor Warns of Phishing Attacks After Third-Party Email

  • SatoshiLabs (Trezor) — Trezor customer email communications sent via third-party email provider (help@trezor.io)
    Vulnerable versions: Third-party email/marketing provider integration; exact vendor unconfirmed as of 2026-09-10
    Fixed in: Malicious landing-page domain taken down by Trezor; provider-side remediation not yet publicly confirmed
  • BitBox (Shift Crypto) — BitBox customer newsletter/email communications
    Vulnerable versions: Suspected shared third-party newsletter provider; exact vendor unconfirmed
    Fixed in: Not publicly confirmed

Remediation for Trezor Warns of Phishing Attacks After Third-Party Email

Immediate actions

  • Do not click links in the 'Critical Security Alert: STM32 Entropy Vulnerability' email or any unsolicited Trezor/BitBox security alert; verify any advisory via the vendor's official app or website, never via an emailed link
  • Report the phishing email to Trezor or BitBox support channels and delete it without interacting
  • Never enter a seed phrase, recovery phrase, or passphrase into any web page reached via an emailed link

Workarounds

  • Treat any unsolicited 'critical vulnerability' email about a hardware wallet as phishing by default; confirm real advisories only via the vendor's official app, verified social media, or its own blog domain directly

Longer-term hardening

  • Vendors: audit and rotate credentials for all third-party email/marketing/newsletter platforms and enforce MFA on those accounts
  • Vendors: monitor SPF/DKIM/DMARC-passing mail sent through third-party ESPs for anomalous campaign activity, not just spoofed-domain mail
  • Vendors: minimize customer PII (email addresses) held by or shared with third-party marketing and fulfillment providers, and contractually enforce data deletion after a partnership ends

Timeline of Trezor Warns of Phishing Attacks After Third-Party Email

  • Trezor discloses unauthorized access to its third-party support ticketing portal, later found to affect roughly 66,000 (revised to 80,689 in March 2024) customers' names and emails; the exposure was followed by phishing attempts against affected users.
  • Trezor's fulfillment/logistics partner ShipMonk notifies Trezor of unauthorized access to its systems, exploiting a critical SQL-injection flaw (CVE-2026-72898, CVSS 10.0) in ShipMonk's Metabase analytics deployment.
  • Trezor publicly discloses the ShipMonk breach, initially affecting close to 14,000 customers' shipping addresses, names, emails, and phone numbers.
  • ShipMonk informs Trezor that the breach also exposed historical order data from a prior partnership period (November 2019 - August 2021) that should have been deleted.
  • Trezor updates its disclosure: the ShipMonk breach total reaches roughly 81,000 customers (about 67,000 additional US customers) after ShipMonk failed to delete retained data per its contract with Trezor.
  • Security researchers (Casa's Nick Neuman, independent researcher Jameson Lopp) and multiple outlets report the Trezor and BitBox phishing emails passed SPF/DKIM/DMARC checks and were likely sent via a shared, compromised third-party marketing/email provider used by several cryptocurrency companies.
  • Trezor takes down the malicious domain linked from the phishing email and opens an investigation into how attackers gained the ability to send mail as its official domain.
  • Trezor warns customers that its third-party email provider was breached and used to send a phishing email titled 'Critical Security Alert: STM32 Entropy Vulnerability' from the legitimate help@trezor.io address, falsely claiming an STM32 microcontroller entropy flaw could expose seed phrases to brute-force attack.
  • BitBox's preliminary review concludes it is very likely that its newsletter/email provider was compromised.
  • BitBox posts an early-morning warning on X that a phishing email impersonating BitBox is circulating and opens an investigation.

Sources cited for Trezor Warns of Phishing Attacks After Third-Party Email

More in phishing

Detection coverage for TL-2026-2432

As of 2026-09-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2432 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats