Invest1 publisher2 min readPublished
Trezor's spoofed alert reused the language of the $112.7m Coldcard exploit
The email telling Trezor owners their recovery phrases might lack entropy came from a real trezor.io address and passed DKIM, SPF and DMARC, and it described a defect close to the one that took 1,778.84 BTC from Coldcard users.
The Investor · Invest desk

What happened
- Trezor told users on September 9, 2026 that attackers had used its third-party email provider to send out a bogus security notice, and said its wallets and devices were unaffected.
- The message carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and claimed Trezor engineers had found a design defect in the STM32 chips used in its products.
- One recipient said the mail arrived from [email protected], followed the Sendinblue campaign path, and passed the DKIM, SPF and DMARC authentication checks.
- Trezor blocked the sending domain and began investigating how its legitimate sending infrastructure was used, publishing its alert just after 4:30 PM Eastern, hours after users flagged the emails.
- Nick Neuman, co-founder and CEO of Casa, said BitBox users appeared to be seeing a similar trend and that a common marketing email provider may have been breached.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- constraint A wallet maker can only harden what it builds, and the customer list lives in services it buys. The defensive spend has to move to suppliers whose code and access controls sit outside its own audits.
- exposure If a shared marketing platform was the entry point, customers of several hardware wallet brands are reachable from one compromised sending account.
- contradiction Vendor comparisons still carrying 13,689 for Trezor understate the company's own September count by 67,000, so any ranking built on that table is ranking a number the company has since replaced.
- decision Each wallet maker now has to choose between keeping a marketing email channel its own customers are being told to distrust and giving up the only fast route it has for a genuine security notice.
The arithmetic sits in the two columns this report keeps apart. Trezor's ShipMonk exposure now stands at 80,689 customers, after old US order records from 2019 to 2021 turned out to have been stored and exposed [9]. SafePal's order-tracking plugin exposed roughly 39,798, with seed phrases, private keys and wallet credentials not compromised in that case [8]. Call it 120,487 people whose contact details are out [1]. Memeburn's August table filed both companies under data breaches and Coldcard under device exploit [11]. The Coldcard column reads differently: Galaxy Research confirmed 190 victims directly on August 14 and at least $112.7m in bitcoin taken through firmware flaws, 1,778.84 BTC [12]. That is about $593,000 per confirmed victim, and it values the stolen coin at about $63,356 each, so the dollar figure moves with the price while the coin count stays fixed [3][6].
The fake notice told recipients that one device in four could be compromised and that their recovery phrases might not carry enough entropy, language the report says closely resembled the issues in the Coldcard attack [4]. A real firmware failure at one vendor hands a phishing operator a technically credible story to tell the customers of every other vendor.
The checks the message passed certify that a server is authorised to send mail for a domain and leave the question of who is operating that authorised account untouched [3]. So the catch came from Trezor reading its own outbound mail, and Decrypt reported that Trezor recognised the message as fake and warned readers not to click the links [7].
Sort the incidents by supplier: an email platform sent the September notice, and ShipMonk held the old order records [1][9]. Global-e held the order details and contact information exposed in Ledger's January incident, with the customer count undisclosed, and a third-party order-tracking plugin held SafePal's [10][8]. Phishing off that kind of list has already reached Ledger customers through physical mail [15].
My read is that the volume is in the trust layer and the money, so far, is in firmware. Chainalysis put crypto scams and fraud at $17bn in 2025, which makes the entire Coldcard total 0.66 per cent of a single year of fraud [13][4]. The counter-case is that reach converts, and nobody in this material has published a conversion rate for a single email campaign. If a hundred of those 120,487 contacts were drained at Coldcard's average per victim, that is about $59m, and a marketing email provider stops being a line item [8]. If attributed losses from the September wave stay near zero, the review budget stays where the $112.7m actually went [12].
What to watch
- Whether any dollar loss is ever attributed to the September 9 campaign, which would give the trust-layer risk its first conversion rate.
- Whether Trezor names the email provider it used, and whether BitBox confirms a shared platform was compromised.
- Whether the ShipMonk figure moves again as further archived order records surface.