Trezor announced on Wednesday that a breach at its third-party email provider enabled attackers to distribute phishing emails disguised as critical security warnings. The fraudulent messages claimed an STM32 hardware flaw weakened recovery phrases on some devices, falsely stating the defect affected one in four units. Trezor confirmed the alert was not from them, took down the malicious domain, and is investigating how access to its legitimate domain was gained.

Security researchers indicated the campaign may extend beyond Trezor, with similar emails targeting BitBox users suggesting a broader compromise of hardware-wallet email providers. Casa CEO Nick Neuman and Chief Security Officer Jameson Lopp warned that malicious emails claiming bad random number generators were being sent without appearing spoofed. This incident follows recent breaches involving Coldcard exploits and ShipMonk data leaks that exposed customer information for sophisticated phishing attempts.