Trezor's email provider has been breached

andreyazimov 15 points 3 comments September 09, 2026
twitter.com · View on Hacker News

Discussion Highlights (2 comments)

toomuchtodo

https://archive.today/H4hbC "Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain."

io84

Their devices have never been [known to be] remotely breached, but still… 2022: Their Mailchimp account breached 2024: Their support ticket portal breached 2025: Support contact form sent phishing via official auto-replies Aug 2026: Shipping partner ShipMonk breached Sep 2026: Email provider breached Anything Trezor knows about you should be considered thoroughly compromised.

Semantic search powered by Rivestack pgvector
6,054 stories · 55,020 chunks indexed