"Our third-party e-mail provider has been breached. Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link," Trezor warned.
Trezor's Wednesday warning and immediate response
Trezor — the maker of cryptocurrency hardware wallets — told customers on Wednesday that attackers who breached its third‑party email provider were sending fraudulent messages pretending to be from the company. The vendor said it has taken down the domain used to send the messages and that an investigation is underway, including work to determine how the attackers obtained access to Trezor’s legitimate domain.
What the phishing messages claimed: STM32 entropy and seed exposure
According to Trezor, the fake emails used the address help@trezor.io and were titled "Critical Security Alert: STM32 Entropy Vulnerability." The messages alleged a "hardware microcontroller vulnerability" in the STM32 microcontrollers used in Trezor cold storage wallets and warned that the flaw could expose wallet seeds to brute‑force cracking. Trezor explicitly told customers those emails were not genuine and advised recipients not to click any links.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleShipMonk breach and expanded customer impact
The email‑provider incident follows an August disclosure by Trezor that attackers had compromised ShipMonk, its shipping and logistics provider, and stole order data including full names, shipping addresses, email addresses, and phone numbers. Trezor initially said the ShipMonk breach affected nearly 14,000 customers; a follow‑up investigation disclosed on Friday raised the U.S. impact by 67,000 more customers, bringing the total to 81,000.
Trezor said the ShipMonk incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
Metabase zero‑day, ShinyHunters extortion, and the mechanics reported
BleepingComputer reported that breach notification emails seen by the outlet said attackers had exploited a vulnerability in the Metabase analytics platform to access ShipMonk systems. In early August, Metabase acknowledged that threat actors exploited a critical SQL injection zero‑day vulnerability to breach customer instances, gain administrator access, and steal data. BleepingComputer also reported that ShipMonk received extortion emails from the ShinyHunters gang after the breach.
What this means for security teams, affected customers, and logistics providers
- Security teams and incident responders: watch for phishing leveraging the "Critical Security Alert: STM32 Entropy Vulnerability" subject line and for fraud that uses legitimate domains after third‑party email providers are compromised. Trezor's notice that the domain was taken down is a containment step, but investigators are still examining how attackers acquired access to the legitimate domain.
- Affected customers and end users: many of the ShipMonk‑exposed records included full names, shipping addresses, email addresses, and phone numbers; Trezor customers whose orders fell between May 10 and August 8, 2026, in the named countries were among those impacted. Trezor's direct guidance to users — not to click links in the fake "Critical Security Alert" email — is the explicit, contemporaneous mitigation the company offered.
- Logistics and procurement leaders at companies using third‑party platforms: the ShipMonk incident traces to an exploited Metabase vulnerability, underlining the risk chain from analytics platforms to customer data. The reported ShinyHunters extortion attempt further highlights the post‑breach monetization routes attackers pursue.
Two parts of this episode stand out in the record: first, attackers are leveraging breaches of third‑party services to impersonate trusted brands and push high‑urgency phishing narratives — in this case, an alleged STM32 microcontroller flaw that would compromise wallet seeds. Second, the ShipMonk disclosure shows how a single exploited platform instance can cascade into tens of thousands of exposed customer records across multiple countries.
An industry data point included in the reporting underlines the operational challenge: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." The Blue Report 2026, cited in the source material, measures defenses across many simulations and underscores that initial containment and credential hygiene are pivotal once adversaries obtain access.
The immediate concrete steps named in the record are limited: Trezor has taken down the domain used by the phishing campaign and is investigating both the email‑provider breach and how attackers accessed the legit domain; ShipMonk and Metabase have acknowledged exploitation related to an SQL injection zero‑day in Metabase; and extortion messages were traced to the ShinyHunters gang. Beyond those facts, the public record provided here leaves open the technical details of the email‑provider compromise and the final scope of any stolen materials tied to the phishing operation.
Original reporting: https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/




