
Three Trezor incidents in 28 days, and none of them touched a wallet
Users of Trezor and BitBox received fake security emails this week, Cointelegraph reports. Neither company's devices were touched. Their mailing lists were.
Hardware wallet phishing needs an address list, and it now has one. Add the disclosed figures and 81,000 customer records have come out through suppliers in 28 days. The number of compromised wallets across all three events is zero.
Twenty-eight days, three suppliers
- 13 August. A breach at the fulfilment company ShipMonk exposes nearly 14,000 Trezor customers.
- 4 September. A further 67,000 US Trezor customers turn out to be affected, with orders going back years.
- 10 September. Phishing emails reach Trezor and BitBox users. Trezor says its email provider was breached; BitBox says its newsletter provider was likely compromised, and that several bitcoin companies appear to have been hit through a shared one.
The subject line that does the work
The Trezor messages carried the subject line Critical Security Alert: STM32 Entropy Vulnerability. That wording is the interesting part.
“Critical Security Alert: STM32 Entropy Vulnerability”
— Subject line of the phishing emails sent to Trezor users, Cointelegraph, 10 September 2026
Cointelegraph, 10 September 2026
STM32 is a real family of microcontrollers, and hardware wallets do use chips from it. Entropy is a real thing too: it is the randomness a wallet draws on when it generates your seed. A weak-entropy bug in the chip that makes your keys would be exactly the emergency the subject line claims.
That is why this lure works on the people it is aimed at. A generic scam email fails a technical reader in one line. This one names the component and the failure mode, and a Trezor owner who has read about seed generation will recognise both.
The advice from both companies is short: do not click links in these messages.
None of them ever held a key
Look at where each incident happened. A fulfilment company packs and ships the boxes. An email provider sends the receipts. A newsletter service sends the announcements. None of them ever holds a private key, and all three hold the list of people who own one.
BitBox's line about a shared provider is the part worth keeping. If several bitcoin companies buy their mailing from the same vendor, that vendor is a single point of failure for the customer lists of an entire industry, and no amount of device security touches it.
We covered the ShipMonk disclosure on 4 September and made the same argument about a medical breach in the days after: what leaks from a supplier comes back as a targeted approach to the customer, months later.
What actually changes for an owner
The practical position has not changed. A hardware wallet protects the key, and the key is the thing that moves money. A leaked address book protects nothing and enables the letter that asks you to hand the key over.
Cointelegraph says it asked both companies for more and had no reply before publication. Until they answer, the count stands at three suppliers, 81,000 records and no compromised devices.
This piece is informational, not a recommendation to buy, sell, or hold any asset.

Comments (0)
No comments yet — be the first!
The market talks all day. We write when it says something
Short, and it tells you why it came
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
288AI





