Security1 publisher2 min readPublished
Attackers sent Trezor customers a fake STM32 alert from [email protected]
Trezor says the phishing came through its breached third-party email provider, arriving from its own address at a customer list that August's ShipMonk theft, now put at 81,000 people, had already exposed.
The Watch · Security desk

What happened
- Trezor told customers on Wednesday that threat actors who breached its third-party email provider are using that access to send them phishing mail.
- The messages were sent from [email protected], an address on Trezor's own live domain rather than from a lookalike.
- The fake alert, subject line Critical Security Alert: STM32 Entropy Vulnerability, claimed a flaw in the STM32 microcontrollers used in Trezor cold storage wallets could expose seeds to brute-force cracking.
- Trezor disclosed in August that attackers who hacked logistics provider ShipMonk stole order data, and later raised the count from nearly 14,000 customers to 81,000 after finding 67,000 more in the US.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Whoever holds the ShipMonk order records knows which named person at which street address bought a cold wallet, so this phishing goes to a pre-qualified list rather than a spray.
- capability A breached email provider hands an actor the vendor's own sending reputation, which makes the standard check on a sender address return the wrong answer for the recipient.
- constraint Trezor's remediation reaches the attackers' landing domain but not the trust question, because it cannot yet say how the provider was entered or how long its outbound mail was in someone else's hands.
- precedent The record on Trezor's customer-facing path is one of supplier compromise rather than product compromise, which sets the expectation that the next incident touching its customers also starts at a vendor.
The asset taken was sender reputation. Trezor says it is still investigating how the attackers got access to its legitimate domain [4], and until that is answered the working position is that mail addressed from [email protected] [2] left the infrastructure Trezor pays to deliver its real notices [16]. The sender did not need a lookalike domain. The lure then borrowed a true detail: Trezor cold storage wallets do use STM32 microcontrollers, and the fake alert hung an entropy flaw on that part [3]. Trezor's guidance to recipients is one line, do not click any link [5].
The recipient list has been in circulation since August. Order records taken from ShipMonk carried full names, shipping addresses, email addresses and phone numbers [6], which is an inventory of people who bought a hardware wallet and the address it shipped to. Trezor first put that at nearly 14,000 customers, then said on a Friday that a follow-up investigation had found 67,000 more in the US, for 81,000 total [7]. The second tranche is 4.8 times the first [13]. Customers in Brazil, Colombia, Italy, Portugal, Sweden and the UK who received orders between May 10 and August 8, 2026 were also in scope [8].
Keep the ShipMonk mechanism and the ShipMonk actor separate. The mechanism is documented in the notification emails, which said the attackers exploited a vulnerability in Metabase [9]; Metabase said in early August that a critical SQL injection zero-day was used to gain administrator access to customer instances and steal data [10]. The actor is thinner. BleepingComputer reports that ShipMonk received extortion emails from ShinyHunters after the breach [11], and that detail rests on its reporting rather than on a ShipMonk statement. Nothing in the record connects that crew to the email provider, and Trezor has named neither the provider nor the entry point [4].
The consistent element is the supplier. A third-party support ticketing portal in January 2024 gave up roughly 66,000 users' names, usernames and email addresses [12]; ShipMonk followed in August [6]; the email provider is the current one [1]. Three separate providers in the same customer path since the start of 2024 [15], and 147,000 records across the two incidents that carry published counts, with unknown overlap between the sets [14]. Each of those vendors held either the customer list or the right to speak as Trezor.
The domain takedown ends this run of mail [4]. What it leaves behind is a customer base whose shipping details are already out [6] and whose cheapest authenticity check, the sender address, belonged to someone else for a period Trezor has not yet defined [4].
What to watch
- Whether Trezor names the email provider and the entry point, which would show whether other brands sending from that platform were also used.
- Whether the 81,000 ShipMonk figure moves again, given the first revision added 67,000 US customers to the original count.
- Whether ShinyHunters or anyone else claims the access to Trezor's sending domain, which would link the stolen order data to the mail channel.