Loading prices...
All news
An intact matte hardware wallet standing beside a burst-open envelope with a fan of blank coral cards spilling out across the floor

Three Trezor incidents in 28 days, and none of them touched a wallet

10:55 · 10.09.2026
Source: Cointelegraph
2

Users of Trezor and BitBox received fake security emails this week, Cointelegraph reports. Neither company's devices were touched. Their mailing lists were.

Hardware wallet phishing needs an address list, and it now has one. Add the disclosed figures and 81,000 customer records have come out through suppliers in 28 days. The number of compromised wallets across all three events is zero.

Twenty-eight days, three suppliers

  • 13 August. A breach at the fulfilment company ShipMonk exposes nearly 14,000 Trezor customers.
  • 4 September. A further 67,000 US Trezor customers turn out to be affected, with orders going back years.
  • 10 September. Phishing emails reach Trezor and BitBox users. Trezor says its email provider was breached; BitBox says its newsletter provider was likely compromised, and that several bitcoin companies appear to have been hit through a shared one.

The subject line that does the work

The Trezor messages carried the subject line Critical Security Alert: STM32 Entropy Vulnerability. That wording is the interesting part.

Critical Security Alert: STM32 Entropy Vulnerability

Subject line of the phishing emails sent to Trezor users, Cointelegraph, 10 September 2026

Cointelegraph, 10 September 2026

STM32 is a real family of microcontrollers, and hardware wallets do use chips from it. Entropy is a real thing too: it is the randomness a wallet draws on when it generates your seed. A weak-entropy bug in the chip that makes your keys would be exactly the emergency the subject line claims.

That is why this lure works on the people it is aimed at. A generic scam email fails a technical reader in one line. This one names the component and the failure mode, and a Trezor owner who has read about seed generation will recognise both.

The advice from both companies is short: do not click links in these messages.

None of them ever held a key

Look at where each incident happened. A fulfilment company packs and ships the boxes. An email provider sends the receipts. A newsletter service sends the announcements. None of them ever holds a private key, and all three hold the list of people who own one.

BitBox's line about a shared provider is the part worth keeping. If several bitcoin companies buy their mailing from the same vendor, that vendor is a single point of failure for the customer lists of an entire industry, and no amount of device security touches it.

We covered the ShipMonk disclosure on 4 September and made the same argument about a medical breach in the days after: what leaks from a supplier comes back as a targeted approach to the customer, months later.

What actually changes for an owner

The practical position has not changed. A hardware wallet protects the key, and the key is the thing that moves money. A leaked address book protects nothing and enables the letter that asks you to hand the key over.

Cointelegraph says it asked both companies for more and had no reply before publication. Until they answer, the count stands at three suppliers, 81,000 records and no compromised devices.

This piece is informational, not a recommendation to buy, sell, or hold any asset.

Published: 10:55 · 10.09.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!

The market talks all day. We write when it says something

Short, and it tells you why it came