Trezor notices and updates
Keep the complete incident email, its headers, any envelope, the date received, and later updates. Save a copy before deleting or reporting a suspicious message.
Hall Attorneys is investigating Trezor-related data exposure and phishing. In a September 9, 2026 statement shown in the source screenshot, Trezor reported a breach of its third-party email provider and warned that an email titled 'Critical Security Alert: STM32 Entropy Vulnerability' was a phishing attempt. This update also covers the earlier ShipMonk order-data breach. A connection between the two events has not been established.
2026 · affected-person count not disclosed
U.S. customers disclosed September 4, 2026
November 2019 through August 2021
Could this be me?
Preserve the September 9 security-alert email if you received it. For the earlier ShipMonk incident, a verified breach notice, order timing, and fulfillment records can help identify a possible connection. These are different indicators, and receiving the phishing email does not establish inclusion in the ShipMonk breach.
Trezor's September 9 statement identifies 'Critical Security Alert: STM32 Entropy Vulnerability' as phishing. Save the original message, full headers, received time, and screenshots without following its links or downloading attachments.
Preserve the complete message, its headers, and any follow-up. Verify the sender and navigate to Trezor's official website independently rather than using an unexpected link or phone number.
The September 4 ShipMonk disclosure concerns approximately 67,000 U.S. customers whose orders date from November 2019 through August 2021. Save the order confirmation, invoice, delivery record, and the address used at the time.
Trezor's initial notice covered recent orders delivered in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The company initially reported 11,742 fully exposed and 1,947 partially exposed customers.
Check shipping notices, tracking pages, labels, return records, support messages, and delivery updates for ShipMonk or another fulfillment-provider reference tied to the Trezor order.
A purchase from Amazon or another independent retailer does not necessarily appear in Trezor's direct-order data. Preserve the receipt and identify the actual seller and shipper before assuming a connection.
Keep the communication, envelope, caller information, and any related account alerts. Do not share a wallet backup, recovery seed, PIN, passphrase, password, or remote access to a device.
Check your records
Search your own records for the company and fulfillment names. Use official Trezor channels to verify a notice, and never enter a wallet backup into a website or disclose it to someone contacting you.
Answer at a glance
September 9 email-provider update: In the @Trezor statement reproduced in the source screenshot, Trezor says its third-party email provider was breached. It identifies the email titled 'Critical Security Alert: STM32 Entropy Vulnerability' as phishing, says the message did not come from Trezor, and tells recipients not to click its links.
Trezor says it took down a domain and was investigating the situation, including how attackers gained access to its legitimate domain. The statement does not name the email provider, quantify affected recipients, specify all data accessed, or establish a connection to ShipMonk. The email's vulnerability claim is part of the phishing lure; this warning does not establish an actual STM32 flaw in Trezor devices.
Trezor says ShipMonk, one of its shipping providers, informed it on August 10, 2026 of unauthorized access to systems containing customer order data. Trezor's August 13 notice initially identified 11,742 customers with full exposure and 1,947 customers with partial exposure.
On September 4, Trezor disclosed that ShipMonk had provided a further update two days earlier. According to Trezor, approximately 67,000 additional U.S. customers who ordered between November 2019 and August 2021 had names, email addresses, phone numbers, shipping addresses, and order numbers exposed.
Trezor says it had repeatedly requested and received written assurances that older order data was deleted in accordance with its contract and data policy, but later learned the records remained in ShipMonk's systems. The public record reviewed for this page does not yet establish why the data remained, the precise unauthorized-access period, or whether the reported counts contain any overlap.
For the ShipMonk incident, Trezor says its systems, products, and devices were not compromised. The reported order data does not include wallet backups or recovery seeds. That earlier assurance should not be treated as a complete assessment of the September 9 email-provider incident. Contact information tied to a hardware-wallet purchase may support highly tailored phishing, impersonation, fraudulent letters, or physical-security threats.
This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.
Trezor says the approximately 67,000 additional customers placed orders during this period and that ShipMonk retained records Trezor understood had been deleted.
Trezor says its shipping provider reported unauthorized access to systems containing customer data.
Trezor initially reported 11,742 customers with full exposure and 1,947 with partial exposure, or approximately 13,689 customers in total.
Trezor says ShipMonk informed it that older U.S. order records were also involved in the incident.
Trezor publicly announced the additional U.S. customer group and said all newly affected customers had been emailed directly.
The @Trezor statement shown in the source screenshot reports a third-party email-provider breach, identifies the STM32 security-alert email as phishing, and says a domain was taken down while the investigation continued. The scope and any relationship to ShipMonk remain unestablished.
Reported data categories
The September 9 email-provider statement does not specify the full data accessed or the number of people affected. The categories below refer to the earlier ShipMonk fulfillment and order records, which can reveal how to contact a customer and where a hardware wallet was delivered.
Important distinction
For ShipMonk, Trezor says its systems and devices were not compromised, and the reported exposed fields do not include recovery seeds or private keys. The September 9 warning does not establish a device vulnerability or theft of wallet keys; it also does not provide a complete forensic assessment of the email-provider breach.
Who may want to contact us
People who received the September 9 phishing email may wish to preserve it and document any resulting harm. The email-provider statement does not define a complete affected group. Separately, the September 4 ShipMonk expansion covers approximately 67,000 U.S. customers with orders from November 2019 through August 2021, in addition to the initial group in seven countries.
Recipients of the fraudulent STM32 security-alert email, including people who clicked a link, downloaded a file, disclosed information, or experienced a loss
U.S. customers who ordered directly from Trezor between November 2019 and August 2021 and received an incident notice
Customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal included in Trezor's August 2026 notice
People whose current or former home address was associated with an affected Trezor order
Affected customers who receive targeted wallet-themed phishing, fraudulent calls or letters, impersonation attempts, or physical threats
People who spend time or money responding to misuse connected to the exposed order information
What to preserve
Preserve enough information to document the affected transaction and any resulting harm, but do not send wallet credentials, a recovery seed, cryptocurrency holdings, passwords, or complete financial-account information through an ordinary contact form.
Keep the complete incident email, its headers, any envelope, the date received, and later updates. Save a copy before deleting or reporting a suspicious message.
Preserve the invoice, order confirmation, order number, seller, shipping notices, tracking history, delivery country, and address used at the time.
Save labels, return instructions, tracking pages, or support messages that identify ShipMonk or another shipping provider associated with the order.
Keep wallet-themed emails, texts, caller details, fake support messages, account alerts, and screenshots of websites or profiles used in an impersonation attempt.
Preserve fraudulent letters and envelopes and document any threat. Contact local emergency services if there is an immediate safety concern.
Maintain a dated log of time spent securing accounts, professional or security expenses, lost funds, replacement costs, and other concrete effects.
Investigation focus
Hall Attorneys is reviewing the reported email-provider breach and phishing campaign, the earlier ShipMonk order-data exposure, notice and protective measures, and resulting harm. The investigation does not assume that the two events share an attacker, cause, or affected customer list.
Public records reviewed
The September 9 update relies on the supplied screenshot of a statement attributed to Trezor's @Trezor account on X. The original post URL was not available for independent verification during this review. The screenshot is linked below as a source alongside the earlier ShipMonk notice and reporting; it does not establish the email-provider incident's full scope.
Trezor (@Trezor on X; supplied screenshot) ·
The supplied screenshot shows a September 9 @Trezor statement reporting an email-provider breach, identifying the STM32 security-alert email as phishing, and describing a domain takedown and ongoing investigation.
Read source: September 9 email-provider breach warning (source screenshot)CyberInsider ·
Reports Trezor's expanded disclosure, the older U.S. order window, the customer information involved, and Trezor's statements concerning data deletion and device security.
Read source: Trezor Says Data of Another 67,000 US Customers Exposed in BreachTrezor ·
Trezor's initial incident notice identifies ShipMonk, the first reported customer groups, exposed data categories, notification process, and wallet-safety guidance.
Read source: Recent customer data exposed in shipping provider incidentThe Block ·
Contemporaneous reporting on the additional U.S. customers, 2019–2021 order records, exposed fields, and Trezor's September 4 statement.
Read source: Trezor says ShipMonk breach affected another 67,000 customersFederal Trade Commission ·
Official consumer guidance for recognizing, reporting, and responding to phishing messages.
Read source: How To Recognize and Avoid Phishing ScamsContact the firm
Tell Hall Attorneys when you received the suspicious email or breach notice, whether you clicked a link or disclosed information, and any resulting expense or loss. For ShipMonk, include your order date and country. Do not send a recovery seed, wallet backup, PIN, passphrase, password, cryptocurrency balance, or complete financial record in an initial message.
Frequently asked questions
In the @Trezor statement shown in the supplied source screenshot, Trezor reports a breach of its third-party email provider and warns about a phishing email titled 'Critical Security Alert: STM32 Entropy Vulnerability'. It says a domain was taken down and the investigation was ongoing. The original post URL was not independently verified during this review.
Trezor's September 9 statement identifies that email as phishing and says it did not come from Trezor. Do not click its links, download its attachments, or enter a recovery seed or wallet backup. The message is not evidence of a confirmed STM32 vulnerability in Trezor devices.
A connection has not been established. The September 9 statement concerns an email provider; the earlier ShipMonk notices concern shipping and order records. The approximately 67,000 additional U.S. customers and approximately 80,689 conditional total refer to ShipMonk, not the email-provider incident. The September 9 statement does not give an affected-person count.
Stop interacting with the message and preserve the original email, headers, received time, and any evidence of what you clicked or disclosed. Navigate independently to trezor.io/support for official assistance. If you entered a recovery seed, wallet backup, or other secret, seek official support promptly and explain what happened without sending the secret itself. Keep records of suspicious transactions, expenses, and losses.
Trezor initially reported approximately 13,689 affected customers. On September 4, 2026, it said approximately 67,000 additional U.S. customers were affected, bringing the reported total to approximately 80,689 if the groups do not overlap.
Trezor says the newly disclosed group consists of U.S. customers who ordered between November 2019 and August 2021. Its August notice concerned a separate recent-order group in the United States and six other countries.
Trezor says the newly identified records contained names, email addresses, phone numbers, shipping addresses, and order numbers.
For the ShipMonk breach, Trezor says its own systems and devices were not compromised and the reported fields do not include private keys or recovery seeds. The September 9 email-provider warning does not establish that devices or wallet keys were compromised, but it does not provide a complete forensic assessment. Never enter wallet secrets into a site reached through an email.
For ShipMonk, Trezor says it emailed affected customers directly. Verify notices through Trezor's official website and preserve your order records. For the September 9 event, keep the suspicious email if received, but do not treat it as proof of ShipMonk exposure. No complete affected-person list for the email-provider incident is established in the statement reviewed here.
Never share a wallet backup, recovery seed, PIN, passphrase, password, remote device access, or cryptocurrency balance with someone who contacts you. Trezor says it will never ask for a wallet backup.
No. This page describes an investigation by Hall Attorneys and does not state that the firm has filed a lawsuit concerning Trezor or ShipMonk.
Attorney Advertising
Hall Attorneys is not affiliated with Trezor or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.