Trezor Confirms Two-Stage Breach Affecting 80,000 Customers as Phishing Emails Arrive From Legitimate Domain
Attackers exploited a shipping partner's internal analytics platform and a compromised email provider to run a coordinated credential-theft campaign against hardware wallet owners worldwide.
Trezor confirmed on September 9, 2026, that its third-party email service provider had been breached, enabling attackers to send phishing messages directly from the company's authentic address, help@trezor.io. The attack is the second stage of a broader supply chain compromise that now affects approximately 80,689 customers globally. The first stage began in August with a data breach at ShipMonk, Trezor's fulfillment partner, which exposed customer names, addresses, and phone numbers and gave attackers the targeting data they needed to run the follow-up campaign. Trezor has publicly stated that this is the first time since the company was founded in 2013 that it has experienced a breach exposing customer phone numbers and shipping addresses.
The phishing emails carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and falsely claimed that the microcontrollers used in Trezor devices contained a hardware-level flaw affecting roughly one in four units. The framing was deliberate. The STM32 angle mirrors a real, recent event: a separate entropy vulnerability in Coldcard wallets that caused over $130 million in Bitcoin losses and received extensive coverage in crypto media. By anchoring the false alert to a genuine fear already circulating in the market, attackers made the message credible to technically literate users who would normally be skeptical of unsolicited security warnings. The emails passed DKIM, SPF, and DMARC authentication checks, which are the standard technical filters email clients use to verify that a message genuinely originates from the domain it claims. They passed because attackers sent them through Sendinblue (now Brevo), the legitimate marketing email platform Trezor uses. BitBox hardware wallet users reportedly received the same email, which suggests the compromised email provider is shared by multiple hardware wallet companies.
Trezor stated publicly that its own systems were not penetrated and that no seed phrases, private keys, or wallet backups were exposed. "Our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts," the company wrote in its official blog post. On X, the company was direct: the STM32 alert "is not coming from us, and it's a phishing attempt." Trezor has taken down the phishing domain and is investigating how access to its email provider was obtained. The company also noted that customers who did not receive a notification from [email protected] are not affected by this breach. The Stage 1 ShipMonk breach affected customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
The underlying data exposure traces back to a critical SQL injection flaw in Metabase, an analytics tool used internally by ShipMonk. The vulnerability, catalogued as CVE-2026-72898 with a maximum CVSS score of 10.0, was first exploited on August 3, 2026, and publicly patched one week later. ShipMonk's initial disclosure in August confirmed that 11,742 customers had full personal data exposed and another 1,947 had partial exposure. Trezor expanded that disclosure in early September to include roughly 67,000 additional U.S. customers whose order data from November 2019 through August 2021 had also been compromised, bringing the total to 80,689. Casa co-founder and CEO Nick Neuman, commenting on the email campaign, advised users simply: "Stay frosty and don't trust provider emails that try to get you to take actions via sketchy looking links," Neuman told Decrypt. Casa CSO Jameson Lopp told Decrypt that no legitimate security advisory from Trezor or BitBox had been issued.
The physical safety implications of this breach are significant, particularly for users in emerging markets where hardware wallet adoption is growing fastest. Nigeria ranked second globally in crypto adoption in the 2025 Chainalysis index, and India, Kenya, and Pakistan have all seen rising self-custody adoption as users seek insulation from exchange collapses and currency devaluation. The ShipMonk breach handed attackers a list of known hardware wallet owners with home addresses, a dataset that directly feeds what security researchers call wrench attacks: physical coercion used to extract crypto holdings. CertiK and Yellow.com recorded 52 verified such attacks in the first half of 2026 alone, extracting $124.1 million, a 33.3 percent year-on-year increase in incident count. Southeast Asia, particularly Thailand, Vietnam, and Indonesia, was specifically flagged as a high-volume region for these attacks. In markets where law enforcement response to financial crime is slower, that exposure carries real personal safety risk. The sophistication of the email campaign compounds the problem: in regions where crypto education resources are less widely available, a phishing message that passes every standard authentication check may be more likely to succeed.
Trezor's 90-day post-delivery data deletion policy limited the breach's reach for more recent customers. In response to the ShipMonk incident, the company is also rolling out an Anonymous Delivery option, available in the EU as of September 2026 and expected in the U.S. by year end, which includes dedicated anonymous checkout, unbranded packaging, locker pickup, and immediate deletion of shipping identifiers after delivery. That approach is worth close attention from other hardware wallet vendors and crypto commerce companies, especially those serving markets where data protection laws are either weak or inconsistently enforced. The Trezor incident demonstrates clearly that customer data collected for logistics purposes does not stay in logistics: it becomes a threat vector with a long shelf life.