Incident timing: Customer warning issued September 9, 2026; exact compromise date not specified.
What is known
BleepingComputer reports that Trezor warned customers about fraudulent security-alert emails following a breach of its third-party email provider. The company said the messages were not genuine and advised recipients not to follow their links.
What this does not establish
The phishing message's claim about a hardware vulnerability should not be repeated as a confirmed technical issue. The report describes an investigation into misuse of an email channel, not proof that customers' hardware wallets were compromised.
Business context
Trusted communication infrastructure can become a route for impersonation after a vendor breach. This episode is separate from earlier incidents involving other Trezor service providers. The investigation was ongoing at the time of the cited report.
Source & attribution
Read the original reporting at BleepingComputerAI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.