top of page
Token Trace Logo
Search

Trezor Confirms Sophisticated Phishing Attack After Email Provider Breach

Writer: Token Trace
Token Trace
Sep 9
4 min read

On September 9, 2026, Trezor users began receiving a highly convincing phishing email warning of an alleged critical vulnerability affecting certain Trezor hardware wallets.

The email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” claimed that a hardware defect involving STM32 microcontrollers could result in insufficient randomness during recovery phrase generation, potentially leaving wallets vulnerable to brute-force attacks.

Trezor has since confirmed that the warning is fraudulent and that a third-party email provider used by the company was breached. Trezor specifically warned users not to click any links contained in the message and stated that it is investigating how the attackers gained access to a legitimate domain.

Token Trace received a copy of the phishing email, shown in the screenshots below.




Why This Phishing Email Is Particularly Convincing

Unlike many phishing emails that originate from misspelled or obviously fraudulent domains, this campaign is considerably more sophisticated.

The email received by Token Trace displayed:


Sender: Trezor Security <noreply@trezor.io>

Subject: “Critical Security Alert: STM32 Entropy Vulnerability”

More concerning, the embedded button directing recipients to “Check to see if you're affected” used a link beginning with:

"r.mailing.trezor.io"


To the average recipient, both would appear legitimate.

Token Trace also reviewed the authentication results of the phishing email we received.


The message showed:

SPF: NONE DKIM: PASS with domain trezor.io DMARC: PASS


Email authentication results from the phishing message received by Token Trace.


DKIM uses a cryptographic signature to help verify that a message was authorized by the domain associated with that signature. DMARC then checks whether authenticated domains align with the address presented to the recipient.


The fact that DKIM passed for trezor.io and DMARC also passed helps explain why this phishing email appeared so legitimate. These results are also consistent with Trezor’s statement that a third-party email provider was compromised, rather than this being a conventional attempt to simply spoof a @trezor.io sender address.


Token Trace received the phishing email at a business support address that has not been used to purchase or register a Trezor device. This suggests the campaign may not have been limited exclusively to known Trezor customers, although the source of all recipient addresses has not yet been publicly confirmed.


When attackers gain access to legitimate email infrastructure, many of the usual visual and technical warning signs of phishing may no longer be present.


Users should therefore independently verify unexpected security alerts through official channels rather than relying on the sender address, embedded links, or email authentication results alone.


What Trezor Users Should Do

Anyone who receives an email concerning the alleged “STM32 Entropy Vulnerability” should treat it as phishing.


Users should:

  • Do not click the “Check to see if you're affected” link.

  • Never enter a wallet recovery phrase into a website.

  • Never provide a recovery phrase, private key, PIN, or passphrase to someone claiming to represent Trezor.

  • Do not rely solely on the displayed sender address to determine whether an email is legitimate.

  • Navigate independently to Trezor's website and official channels when checking security announcements.

  • Be especially cautious when an unexpected message claims that funds are at immediate risk.

  • Verify security alerts independently before taking action involving a cryptocurrency wallet.

Trezor has specifically advised recipients of this campaign not to click any links and reiterated that users should never disclose their wallet backup online.


What If You Already Entered Your Recovery Phrase?

If you entered your recovery phrase into a website reached through this phishing email, you should assume that the recovery phrase has been compromised.


A recovery phrase is not simply a password to the hardware device. It can be used to recreate the wallet independently of the original Trezor device.


As a result, changing the device PIN, disconnecting the hardware wallet, closing the phishing website, or deleting the email does not make an exposed recovery phrase safe again.


The safest course is generally to create an entirely new wallet using a new recovery phrase generated through trusted wallet hardware or software and transfer any remaining assets to addresses controlled by that new wallet.

Do not return to the link contained in the suspicious email for instructions on how to do this.


If cryptocurrency has already been transferred without authorization, preserve as much evidence as possible, including:

  • Transaction hashes

  • Wallet addresses

  • Screenshots

  • The original phishing email

  • Email headers

  • URLs

  • Dates and times

  • Any communications associated with the incident


Blockchain transaction tracing can then be used to follow the movement of stolen cryptocurrency and determine whether identifiable exchanges or other services become involved.


Why Sender Verification Wasn’t Enough

This incident highlights an important change in how cryptocurrency users should think about phishing.


A suspicious spelling, unusual sender address, or obviously fake website remains a strong warning sign.


But the absence of those signs does not guarantee that a message is safe.

In this campaign, recipients received an email that appeared to originate from Trezor and contained a link using the legitimate Trezor domain. Trezor itself has confirmed that attackers compromised a third-party email provider and is investigating how they gained access to its legitimate domain.


The safest approach is therefore to evaluate the action being requested, rather than relying solely on how authentic the email appears.


When an unsolicited communication involving a cryptocurrency wallet creates urgency and asks you to verify, recover, synchronize, migrate, or otherwise interact with your wallet, stop and independently confirm the situation through official sources.


And regardless of how legitimate an email or website appears:

Never enter your recovery phrase into a website because an unsolicited email tells you to do so.


Think you may have been affected by this phishing campaign?

Token Trace can help review suspicious blockchain activity and trace unauthorized cryptocurrency transactions. Contact us here.

 
 
bottom of page