S&P 5007,636.36▼0.5% Nasdaq26,253.34▼0.6% Dow52,380.66▼0.8% Russell 2K2,921.23▼1.3% 10-Yr4.84%+3bp VIX16.46+0.74 WTI$97.01▲4.3% Gold$4,445.30▲1.2% EUR/USD1.164▲0.1% BTC$78,305▼0.2% Nikkei65,269▼1.7%
At close · Thu, Sep 10, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureTrezor flags phishing emails sent from its official do…

Trezor flags phishing emails sent from its official domain

The hardware wallet maker said a breach at a third-party email provider allowed phishing to be sent from its domain, and it has taken the domain down while investigating how the attack worked.

Trezor warned users that phishing emails were sent from its official domain after a breach at a third-party email provider, according to The Block. The company cautioned that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” was not sent by Trezor and advised recipients not to click links.

Trezor said it has taken down the domain and is investigating how attackers were able to use its official domain for the phishing messages. It also warned users to recognize the communication as fraudulent.

The Block notes the warning comes after a separate prior incident involving Trezor and its shipping provider, ShipMonk, which exposed personal information of customers. Trezor previously said about 13,700 customers were affected, and later said another 67,000 U.S. customers were also impacted by the same breach.

The Block also reported that BitBox, another Swiss bitcoin hardware wallet maker, saw similar phishing activity on the same day. Separately, it cited earlier research by Ledger’s Donjon team on a hardware vulnerability in a chip used inside the Trezor Safe 7, with Trezor saying at the time that no user funds were at risk.

Latest closeBitcoin $78,304.79 ▼0.2%

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.