U.S. Senate Blocks Clarity Act, Impacting Crypto Regulatory Framework
Analysis-Houthi advance in Yemen puts U.S. in a new bind
Yemeni Government Forces Strike Houthi Vessels in Taiz Region
Xi Sits Down With Modi on First Trip to India in Seven Years
Iraq and Iran to Jointly Investigate Drone Launchers on Border
RBI Rejects Tata Sons Plea to Nix Shadow Lender Tag, Reports Say
Bahrain Declines Participation in Iran Meeting Regarding Hormuz Strait
HDFC Bank Submits Names of Two CEO Candidates to RBI
Oil Supply Risks Rise After Saudi Pipeline Attack
Modi Seeks BRICS Unity as Global Tensions Rise
BRICS 2026: Modi Seeks Bigger Role For Global South
BRICS Countries Call for Maximum Restraint in the Middle East
Trump Signals US Wants Distance From Iran War
Iranian President Urges BRICS to Oppose Targeting of Civilian Infrastructure
Dell Technologies (DELL) Stock Reaches Record Peak as Founder Climbs to Third Wealthiest Globally
Markets Defy Logic: Stocks Surge 1% Despite Scorching Inflation Numbers
Rocket Lab (RKLB) Stock Gains Analyst Support Despite 46% Decline
GE Vernova (GEV) Stock: Is the Recent 23% Decline Creating a Strategic Entry Point?
Iraq Fires Maysan Commander After Drone Attacks on Saudi Arabia’s Pipeline
Tesla (TSLA) Semi Truck Expansion: European Launch Confirmed for 2027
Cathie Wood’s ARK Invest Pivots to Meta (META) and Rocket Lab in September Trading Activity
Nvidia (NVDA) Eyes $10B Stake in Anthropic’s Historic $2 Trillion IPO
General Motors to Develop Domestic Battery Supply Chains Amid Political Tensions
Iraqi Parliament Speaker Emphasizes State Control Over Weapons
Can Venezuela Rescue the Oil Market?
Can China’s Icicle woo global shoppers in a luxury downturn?
After the I.P.O., a Billion-Dollar Bill for Employee Paydays
Trump Criticizes Europe on Immigration, Trade, and NATO Cooperation
Iraqi Parliament Speaker Backs Urgent Investigation into Recent Attacks
Mexican Authorities Investigate Suspected Cartel-Linked Crypto Mining Operation
Iraqi Prime Minister Dismisses Police Chief in Maysan Province
Iran President and Abu Dhabi Crown Prince Hold Meeting in New Delhi
Iranian President Calls on BRICS to Address Unilateral Sanctions
HDFC Bank Submits Names of Two Candidates for CEO Role to RBI
China's Xi Urges Peace at BRICS Summit Amid Middle East Tensions
Donald Trump Voices Support for Irish Unification
U.S.-Canada trade war set to hit hard in midterm battleground states
Why a $5,000 Trump dividend check won’t solve your money woes
Nvidia (NVDA) Stock Analysis: CEO Jensen Huang Reaffirms $4 Trillion AI Market Vision
Xi Jinping Urges BRICS Nations to Uphold Historical Justice at Summit
Citi sees Fed delivering "a dovish hike" next week
Revolut Data Breach: Fraudulent Government Email Leads to Bitcoin Record Leak
Robinhood (HOOD) Crypto Trading Surges 61% Monthly But Lags 38% Behind 2025 Figures
Oil and Gas Markets Signal Winter Crisis and Rising Interest Rates
Hyperliquid (HYPE) Surges Past $82: Whale Accumulates $322M as Token Burn Accelerates
Former Anthropic Employees Resign Over AI Safety Failures, Warn of Existential Risks
War In the Middle East Crisis is Making Clothes More Expensive
Leaders Arrive At Bharat Mandapam
Trump Affirms Friendship with Saudi Crown Prince Amid Pipeline Attack Concerns
Bitcoin (BTC) Rallies Past $79K as CPI Data Shows Mixed Inflation Signals
What Many Miss Regarding the US-China Rivalry: New Economy
BRICS agrees to joint declaration in test of unity despite Mideast tensions
Trump says Iran war likely to end after midterms as Yemen fighting escalates
Maharashtra Pilots Asset Tokenization as India Embraces Blockchain for Power Grids and Bonds
Trump says Iran probably responsible for attack on Saudi pipeline
Trump Suggests Iran Likely Behind Saudi Pipeline Attack
Iran Signals Potential Shift in Nuclear Policy
Ethereum (ETH) Breaks Past $2,600 Despite Rate Hike Concerns, Reaches Multi-Month Peak
Ford Issues Recall for U.S. Vehicles Over Fuel Tank Hazard
Christine Lagarde: Europe seen from Normandy
Canadian boycott of US products pushes grocers to adapt, explore new supply sources
Iran Shifts to Offensive Military Strategy, Lawmaker States
BRICS 2026: Leaders Arrive At Bharat Mandapam
Canada seeks $1tn from investors looking for a haven from Donald Trump
News Quiz for September 12, 2026
Huawei Technologies Develops Large Language Model for Tourism Content
BRICS Members Reach Joint Declaration Condemning Unilateral War
Iran President Confirms Supreme Leader Mojtaba Khamenei is Alive
Chart of the Week: the long shadow of quantitative easing
Trezor Email System Compromised: Phishing Attack Targets Cryptocurrency Wallet Users
Key Takeaways
- Cybercriminals compromised Trezor’s email service provider, enabling them to distribute phishing messages from the company’s legitimate domain
- Recipients received fraudulent alerts about an alleged “STM32 Entropy Vulnerability” prompting immediate device updates
- A parallel phishing campaign targeted BitBox wallet owners, indicating a broader attack on hardware wallet email infrastructure
- Trezor has disabled the compromised domain and initiated a security investigation
- The incident comes on the heels of last month’s ShipMonk breach that compromised information for more than 80,000 Trezor clients
On Wednesday, Trezor publicly acknowledged that cybercriminals had successfully infiltrated its third-party email service provider. The breach enabled attackers to distribute phishing messages that appeared to originate from an authentic Trezor email address.
The fraudulent message bore the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” It falsely asserted that a hardware defect in Trezor wallets could compromise the randomness of recovery seed phrases, thereby jeopardizing user assets.
Trezor responded swiftly via its X account, stating: “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”
According to the company’s statement, the malicious domain has been deactivated while security teams work to determine exactly how unauthorized access was obtained.
The timing of the fraudulent email suggests attackers deliberately capitalized on recent anxiety surrounding the Coldcard security flaw, which resulted in losses exceeding $130 million in Bitcoin.
BitBox Users Face Similar Threats
On the same day, Switzerland-based hardware wallet manufacturer BitBox disclosed that its customer base had also received comparable phishing communications. This development suggests the security incident may extend beyond Trezor’s infrastructure.
Casa’s Chief Executive Officer, Nick Neuman, commented on X that the evidence points to a compromise of a common email marketing platform. “Stay frosty and don’t trust provider emails that try to get you to take actions via sketchy looking links,” he cautioned.
Jameson Lopp, who serves as Chief Security Officer at Casa, reinforced these warnings. He emphasized that malicious actors likely penetrated email service providers utilized by multiple hardware wallet companies, noting that the messages weren’t spoofed but originated from genuine addresses.
Cryptocurrency analyst MHPaz published screenshots of the deceptive email, verifying that it displayed official domain credentials and digital signatures that appeared legitimate.
Recurring Security Challenges
Trezor’s recent security history includes multiple incidents. In the previous month, logistics partner ShipMonk suffered a data breach that exposed personal information of 80,689 customers, including full names, email addresses, telephone numbers, and physical mailing addresses.
At that time, Trezor cautioned that the compromised information could facilitate more sophisticated, personalized phishing operations. Current events have validated those concerns.
Earlier in June, Ledger’s security researchers identified a laboratory-verified hardware weakness in the TROPIC01 chip integrated into the Trezor Safe 7 model. Trezor maintained that the discovery posed no actual threat to customer funds.
Hardware wallet owners are currently being urged to avoid clicking embedded links in security-oriented emails from wallet manufacturers until additional clarity emerges. All alerts should be independently confirmed through official company websites.
To date, no confirmed financial losses have been attributed to this particular phishing operation.
Source: Parameter
ALERT: Trezor warns hackers have breached its email provider and are sending phishing emails from its legitimate domain.