Trezor, BitBox phishing: fake STM32 alert sent via breached email provider

On September 9, 2026, Trezor and BitBox warned that attackers breached a shared newsletter provider and sent a fake “STM32 Entropy Vulnerability” alert from Trezor’s real domain, passing SPF, DKIM and DMARC.

Voxel shield in dark grey with a cracked red @ sign, debris cubes scattered on a dark background

The most convincing phishing email of the month didn’t come from a lookalike domain. It came from Trezor’s own. On September 9 the hardware wallet maker told users that its “third-party e-mail provider has been breached” and that a message titled “Critical Security Alert: STM32 Entropy Vulnerability” did not come from the company. BitBox put out a similar warning the same day.

The email passed SPF, DKIM and DMARC — the three checks mail clients use to decide whether a sender is who it claims to be. The checks weren’t fooled. The message really was sent through a platform authorised to mail on Trezor’s behalf. That is exactly the problem.

Key facts

  • On September 9, 2026, Trezor and BitBox warned users about phishing emails sent through a breached third-party newsletter provider; BleepingComputer reported the incident on September 10.
  • The phishing email, titled “Critical Security Alert: STM32 Entropy Vulnerability”, was sent from Trezor’s real domain and passed SPF, DKIM and DMARC authentication.
  • The email claimed a flaw in the STM32 chips inside Trezor devices could expose seed phrases to brute-force guessing; there is no confirmation that such a vulnerability exists.
  • Trezor says the email is not from the company, users should not click any link, the phishing domain has been taken down and wallets are safe.
  • BitBox said other Bitcoin companies that appear to share the same newsletter provider were also targeted.

What happened to Trezor and BitBox on September 9?

Attackers broke into the third-party service Trezor uses to send its newsletter and used it to mail a fake security alert from the company’s genuine domain. BitBox, which appears to rely on the same provider, warned its own users about the same campaign. Trezor says the devices themselves are not affected and wallets are safe.

According to BleepingComputer, Trezor’s statement was blunt: the email “is not coming from us, and it’s a phishing attempt.” The company took down the phishing domain the links pointed to and is investigating how its sending domain was used. Its guidance is simple: don’t click any link in the message.

BitBox issued a parallel warning and, as CryptoSlate reported, said other Bitcoin companies that appear to use the same newsletter provider were hit too. Which companies, and how many people received the email, had not been confirmed as of September 10.

It is not Trezor’s first supplier problem this summer. BleepingComputer notes that an August breach at the company’s shipping provider ShipMonk exposed the names, addresses, emails and phone numbers of about 81,000 Trezor customers.

Why did a fake STM32 alert look believable?

Because a real weak-entropy incident had just happened. This summer, Coldcard users whose seeds were generated on a 2021 firmware lost more than 1,800 BTC. A warning about chip-level randomness and brute-forceable seeds matched a story hardware wallet owners already knew was possible. The attackers borrowed the plot of a genuine incident.

We covered the aftermath on September 3, when the Coldcard thief started moving stolen BTC through THORChain. Good phishing doesn’t invent a fear; it recycles one. “Your seed may have been generated with weak randomness” sounds exactly like the Coldcard story — and the natural next step, “check or migrate your seed now”, is precisely what a drainer wants you to do.

The rest was technical polish. STM32 is a real family of chips, and “entropy” is a real concept most users can’t verify on their own. Put that into an email that clears every authentication check and arrives from the same sender as last month’s genuine newsletter, and the usual advice to “check the sender” has nothing to catch.

A real incident is the best template for a fake one.

Can you trust an email that passes SPF, DKIM and DMARC?

Not on its own. SPF, DKIM and DMARC prove that a message was sent by a server authorised to use a domain — not that the company actually meant to send it. When the email platform itself is compromised, a phishing message is fully “authenticated”. Treat these checks as proof of origin, never as proof of intent.

Most brands send newsletters through a third-party platform and authorise it in their DNS records. That makes the platform part of the brand’s trust boundary. Whoever gets into the platform inherits the brand’s reputation, its green checkmarks and its subscriber list in a single move.

That subscriber list is the quieter leak in this story. Being on a hardware wallet vendor’s mailing list says something about you: this person probably owns a hardware wallet and holds crypto worth protecting. That is useful metadata for phishers today and for worse actors tomorrow.

What should hardware wallet owners do now?

If you received the email, delete it and don’t click anything. Trezor says wallets are safe; the risk only starts if you typed your recovery phrase somewhere or installed software from a link. If you did either, treat that seed as compromised and move funds to a new wallet with a freshly generated seed.

A short hygiene checklist that holds for any vendor:

  1. Never type your seed into a website, form or pop-up. No legitimate vendor — Trezor, BitBox, Coldcard or anyone else — will ever ask for it.
  2. Verify on official channels. Check any security claim on the vendor’s website or official accounts, typed in by hand, not through links in the email.
  3. Update firmware only through the official app. Never from a download link in an email or a message.
  4. Treat urgency as a red flag. Real security fixes come with changelogs and time, not countdowns.
  5. Use a separate email alias for each crypto vendor. If one list leaks, you know who leaked it and can kill the alias without touching the rest.
  6. Already entered your seed? Move funds now to a new wallet created from scratch on a trusted device.

None of this is an argument against hardware wallets. They remain the right tool for long-term holdings — our cold storage guide and best Bitcoin wallets of 2026 cover how to set one up properly. The device did its job here; the weak link was the email list around it.

Your seed is never the answer to an email.

What it means for self-custody and swaps

Every crypto service that knows your email adds you to another list that can be breached, leaked or abused. The fewer of those lists you are on, the smaller your attack surface. Swapping on SwapZilla needs no account and no email: you pick a pair, compare quotes from several providers side by side, paste a receiving address — ideally one generated by your own hardware wallet — and send. No account means no login to phish and no email of yours on file to leak. It doesn’t make you anonymous, and providers can still run checks on flagged transactions, but it is one less database that knows you hold crypto.

Markets shrugged off the news. According to Yahoo Finance, BTC opened September 10 at $78,292 and traded near $77,940 by 7:19 a.m. ET, with ETH around $2,465, as US August PPI came in at +5.4% year on year versus 5.3% expected.

Final thoughts

Trezor and BitBox disclosed quickly, and there is no sign the STM32 “vulnerability” is real. But the campaign shows where phishing has moved: attackers no longer fake the sender, they borrow it. The defence hasn’t changed. Your seed lives on paper or metal, never in a browser. Firmware comes from the official app. And the fewer places that know both your email and your hobby, the fewer places can be turned against you.

FAQ

Is the Trezor STM32 entropy vulnerability real?
There is no confirmation that the STM32 entropy vulnerability described in the September 2026 phishing email exists. Trezor said the message titled “Critical Security Alert: STM32 Entropy Vulnerability” was not sent by the company and is a phishing attempt. The email borrowed the story of the real Coldcard weak-entropy incident from the summer to sound credible. Trezor says wallets are safe and asks users not to click any link in the email.
Was Trezor hacked in September 2026?
Trezor’s own devices and wallets were not reported as hacked. On September 9, 2026, Trezor said its third-party e-mail provider had been breached and that attackers used it to send phishing emails from Trezor’s real domain. The company took down the phishing domain and is investigating how its domain was used. BitBox issued a similar warning and said other Bitcoin companies sharing the same newsletter provider were also targeted.
What should I do if I clicked the fake Trezor email?
If you only opened or clicked the fake Trezor STM32 email and entered nothing, delete it and do not return to the site. If you typed your recovery phrase anywhere or installed software from the link, treat the seed as compromised: create a new wallet with a freshly generated seed on a trusted device and move your funds immediately. Update firmware only through the official app and verify any security notice on Trezor’s official channels.
Why did the phishing email pass SPF, DKIM and DMARC?
The Trezor and BitBox phishing emails of September 2026 passed SPF, DKIM and DMARC because they were sent through the companies’ real, breached newsletter provider, which is authorised to send mail for their domains. These checks confirm that a server is allowed to send for a domain, not that the company intended the message. When the sending platform is compromised, a malicious email can look fully authenticated.
Does SwapZilla require an email to swap crypto?
No. SwapZilla is a non-custodial swap aggregator that requires no account and no email to swap. You choose a pair, compare quotes from several providers, enter a receiving address such as one from your hardware wallet, and send. Because no email is collected for a swap, there is no SwapZilla login or address list tied to you that could leak in a provider breach like the one that hit Trezor in September 2026. Providers may still run AML checks on flagged transactions.