Trezor has warned customers about a phishing email that landed after attackers breached one of its third-party email providers. The message tells users about a major Trezor wallet security risk. That warning is false, according to the company. Trezor says recipients should not click any links in the email.
What Trezor Told Customers
The phishing email uses the subject line Critical Security Alert: STM32 Entropy Vulnerability. The text appears designed to make people think their hardware wallets are in immediate danger. Anyone who clicks the link may be sent to a website that asks for confidential wallet details. Trezor said the email is not from the company and called it a phishing attempt. The firm has taken down the domain involved and is investigating how attackers gained access to a legitimate domain.
Why the Email Looked Real
Because the email came from a genuine domain, some users might believe it is real. Attentive users often check the sender address before trusting a message. But when the domain is original, a fraudulent email can look more convincing. Trezor has not named the affected email provider. It has also not said how many customers received the message or whether their details were accessed. The company has not reported any loss of cryptocurrency from this campaign.
Separate Breach at ShipMonk
A few weeks earlier, Trezor dealt with a separate breach involving its shipping provider, ShipMonk. That incident exposed names, email addresses, phone numbers, and delivery addresses. Trezor later said 67,000 more customers in the US were affected. The latest email provider phishing campaign did not come from ShipMonk. Trezor has not linked the two incidents or claimed the same attackers were responsible.
What Users Should Do
Customers who received the new email should avoid its links and delete the message. They should never enter their wallet backup on a website or share it with anyone. Hardware wallet users should treat urgent security alerts with care, especially when they ask for seed phrases or private information. If an email creates panic, it is perhaps best to check Trezor’s official channels before acting. The company’s warning is simple: do not click, do not share, and do not trust a message just because the sender domain looks correct.
![]()

