Trezor, the Czech hardware wallet maker, disclosed on social media that an unnamed third-party email provider was breached, allowing attackers to send phishing emails from the company's legitimate domain. The fraudulent message, titled "Critical Security Alert: STM32 Entropy Vulnerability," attempts to trick recipients into taking dangerous action with their wallets.

"Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt," Trezor wrote. "Do not click on any link."

The company said it has taken down the domain used in the attack and is investigating how the attackers gained access to its legitimate email infrastructure. The incident is distinct from the ShipMonk shipping provider breach disclosed in August, which exposed the personal data of more than 80,000 Trezor customers across multiple disclosure waves.

The Phishing Angle Is Not Random

The fake email's subject line references STM32 entropy vulnerabilities, a real category of risk in hardware wallet security. The timing appears calculated. In late July, a firmware flaw in Coinkite's Coldcard hardware wallet led to the theft of more than $116 million in bitcoin after attackers discovered they could reconstruct seed phrases generated by devices running vulnerable firmware dating back to March 2021. The bug caused certain Coldcard models to fall back on a weak software random number generator instead of the hardware's true random source.

Trezor published an advisory clarifying its devices were not affected, noting that its wallets combine multiple entropy sources including device hardware, the connected host, and secure element chips on newer models. The phishing email now exploiting Trezor's email domain appears designed to create confusion, borrowing language from real security incidents to manufacture urgency.

Advertisement

This is a recurring pattern. In late August, Trezor acknowledged a wave of phishing emails claiming a "critical entropy vulnerability in the firmware," fabricating claims about a bug in a 2021 update. The company confirmed attackers were combining data from multiple leaked databases across different crypto services to improve targeting.

AI Is Accelerating the Threat

The cryptocurrency sector is on pace for its worst year of security incidents. Blockchain security firm SlowMist counted 182 security incidents in the first half of 2026, a 50 percent increase over the prior period. Blockaid's figures are even higher, documenting 212 verified exploits and $1.1 billion in losses through June.

What separates 2026 from previous years is how attackers build and execute these campaigns. North Korean state-sponsored hackers, responsible for roughly 55 percent of stolen funds in the first half of the year, have deployed AI for social engineering, deepfakes, and automated vulnerability scanning. The two largest hacks of the year, the $292 million Kelp DAO breach and the $285 million Drift Protocol attack, traced not to smart contract failures but to compromised human signers deceived through sustained social engineering campaigns.

AI is also attacking AI. In May, Blockaid flagged a $175,000 exploit targeting the Grok-BankrBot AI trading agent, where an attacker sent the chatbot a Morse code message that it decoded into a hidden transfer instruction. SlowMist called it an "AI agent trust chain" attack, a category expected to grow as more users delegate transaction authority to autonomous systems.

The Physical Threat Compounds Digital Risk

Data leaks at hardware wallet companies carry a second-order consequence that goes beyond phishing: they enable violent crime. Chainalysis documented 46 physical attacks against cryptocurrency holders in the first half of 2026, with more than $30 million stolen. If the pace continues, 2026 will surpass last year's record $58 million in violent crypto theft.

Advertisement

Home invasions accounted for 37 percent of incidents this year, up from 26 percent in 2023. Attacks targeting family members or acquaintances rather than the holder directly rose to 25 to 30 percent of cases. France alone accounted for nearly two-thirds of all publicly reported wrench attacks, driven partly by a compromise of French tax agency records that gave criminals a list of verified holders.

The ShipMonk breach that exposed Trezor customer shipping addresses falls into exactly this category of enabling data. The company warned in its disclosure that the leaked information "could potentially expose affected individuals to physical security risks." Reports from Help Net Security indicate affected customers have already begun receiving phishing calls and physical letters containing QR codes, arriving at the same addresses tied to their Trezor orders.

What Users Should Do

Trezor's guidance remains consistent: never enter a wallet backup or seed phrase on any website, and treat urgency as a red flag. Any email demanding immediate action should be verified against official Trezor channels before responding.

For the broader ecosystem, the lesson is structural. Third-party vendors remain the weakest link. ShipMonk held SOC 2 Type II certification and was breached anyway. The company had received repeated deletion requests from Trezor and confirmed in writing that customer data had been removed. It hadn't been. Trezor is now rolling out an anonymous delivery option with locker pickup and immediate deletion of shipping identifiers, scheduled for the EU by September and the US by year-end.

Hardware wallets remain the most secure way to hold cryptocurrency. But the infrastructure around them, the email providers, shipping partners, and support ticketing systems, creates exposure that attackers are increasingly willing to exploit. The domain Trezor took down this week will not be the last.