XIYU.NEWS EVENTS

Trezor email provider breach exposes hundreds of thousands of crypto owners to scammers

MonitoringCryptoSecurity incidentFirst tracked 2026-09-11Last changed 2026-09-11

Current outcome

Trezor confirmed that a breach at its third-party email service provider exposed the contact data of hundreds of thousands of crypto owners, who are now being targeted by phishing and social-engineering campaigns. Trezor warned that an email titled "Critical Security Alert: STM32 Entropy Vulnerability" did not come from the company, said it had taken down the malicious domain, and is investigating how attackers obtained access to a legitimate Trezor domain. Although no private keys or funds were directly compromised, the leaked contact data gives attackers the raw material for convincing, personalized phishing aimed at a large population of hardware wallet users. It is also Trezor's second vendor-related incident in quick succession, which puts third-party supply-chain risk for self-custody providers under renewed scrutiny. The phishing messages gained credibility by being sent from a legitimate Trezor domain, meaning standard sender-authentication checks would not flag them. The exposed dataset includes names, email addresses and phone numbers, and in August Trezor disclosed a separate breach at its shipping and logistics provider ShipMonk that leaked order data such as full names, shipping addresses, emails and phone numbers — datasets that can be combined to make impersonation attacks far more persuasive.

Progress timeline

1 material updates
  1. #01
    Initial2026-09-11 16:00 · publication time

    Trezor email provider breach exposes hundreds of thousands of crypto owners to scammers

    Trezor confirmed that a breach at its third-party email service provider exposed the contact data of hundreds of thousands of crypto owners, who are now being targeted by phishing and social-engineering campaigns. Trezor warned that an email titled "Critical Security Alert: STM32 Entropy Vulnerability" did not come from the company, said it had taken down the malicious domain, and is investigating how attackers obtained access to a legitimate Trezor domain. Although no private keys or funds were directly compromised, the leaked contact data gives attackers the raw material for convincing, personalized phishing aimed at a large population of hardware wallet users. It is also Trezor's second vendor-related incident in quick succession, which puts third-party supply-chain risk for self-custody providers under renewed scrutiny. The phishing messages gained credibility by being sent from a legitimate Trezor domain, meaning standard sender-authentication checks would not flag them. The exposed dataset includes names, email addresses and phone numbers, and in August Trezor disclosed a separate breach at its shipping and logistics provider ShipMonk that leaked order data such as full names, shipping addresses, emails and phone numbers — datasets that can be combined to make impersonation attacks far more persuasive.

    Source evidence: techcrunch.com

All events · Back to the feed

XIYU.NEWS APP

Install xiyu.news

Open in a standalone window, check for updates online and read saved pages offline.