TL;DR
- Trezor confirmed a breach at its email provider and warned about a fraudulent message titled “Critical Security Alert: STM32 Entropy Vulnerability”.
- BitBox warned that its newsletter provider may have been compromised and that several Bitcoin companies were affected through a shared provider.
- Security incidents at other logistics providers of the company exposed the data of more than 81,000 customers in the U.S.
The hardware wallet sector is going through a high-tension week. Trezor and BitBox jointly warned about phishing emails disguised as urgent security alerts, after compromises were detected in third-party email service providers used by both companies.
Trezor reported that its email provider had been breached and warned its users that a message circulating under the subject “Critical Security Alert: STM32 Entropy Vulnerability” was fraudulent. The company urged recipients to not click on any links included in that email.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating…
— Trezor (@Trezor) September 9, 2026
Trezor and BitBox in the Crosshairs of Attackers
BitBox also warned about a phishing email that appeared to come from the company. The team’s preliminary review indicated that its newsletter provider may have been compromised, and added that several companies in the Bitcoin ecosystem appear to have been targeted through a shared provider. This suggests a coordinated campaign aimed at the sector’s communications supply chain, rather than targeting each company individually.
There have been several incidents recently. On August 13, a breach at ShipMonk, Trezor’s logistics provider, exposed the data of approximately 14,000 customers. On September 4, Trezor disclosed that another 67,000 U.S. customers had been affected in a separate incident. As for BitBox, in July it confirmed that its devices were not affected by a vulnerability related to random number generation in Coldcard, and in August it released an update fixing two serious firmware vulnerabilities, though no known cases of exploitation or stolen funds have been reported.
A Pattern That Worries the Sector
The accumulation of incidents at third-party providers reveals a structural vulnerability that goes beyond any particular manufacturer. Attackers appear to exploit the weakest links in the chain: logistics, email, and mass communication services.




