The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning

An alleged security warning to wallet customers travelled through the manufacturer's genuine sending channel and passed every technical authenticity check. The test that still holds costs you four minutes.

Torn-open envelope with a broken wax seal, a steel fish hook lying across it, next to it a metal device for key storage and a coin with an embossed Bitcoin symbol
12 min read
Share:

On Wednesday evening, owners of a hardware wallet found an email in their inbox with the subject line “Critical Security Alert: STM32 Entropy Vulnerability”. The message looked like a security warning from the manufacturer Trezor, and it arrived through that company's genuine sending channel. Trezor made clear the same evening that the message had not come from it. That removes the piece of advice which tops almost every guide: look at the sender address.

This article explains how to recognise a forged security warning when the technical authenticity checks in your mail client all report green, and which four minutes of work protect you from the most expensive mistake a crypto investor can make.

What Happened on September 9: A Warning Email Through the Genuine Channel

Trezor said on its account on X on September 9, 2026: “Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link.” According to Decrypt, the post went live at around 4:30 pm US Eastern time, shortly after 10:30 pm in Germany. Recipients had already been reporting the message for hours.

What sets this apart from the usual forgeries is the route the mail took. The Block reports that the messages were sent through the company's legitimate official domain; the target of the attack was an external service provider that the manufacturer uses to send customer mail. Trezor has not publicly named the provider. The company had the linked landing page taken down and announced an investigation. By its own account, the wallet itself was never affected.

For you as a recipient, that means the mail sat in your inbox among genuine messages from the same sender, with the same layout, from the same domain. No typo in the name, no clumsy translation, no suspicious attachment.

STM32 Entropy: Why the Invented Flaw Sounded So Credible

The forgery claimed that developers had found a critical hardware-level flaw in microcontrollers of the STM32 family. Roughly one device in four was affected, the mail said, and the fault weakened the randomness of the recovery phrase. That is how Decrypt describes the content of the message.

Entropy is the cryptographic term for the amount of randomness a key is generated from. The less randomness goes into that step, the smaller the space of possible keys becomes, and the easier one of them is to guess. A genuine entropy weakness would be the gravest finding imaginable for a wallet, because it hits every device in the same production run and not just a single account.

That is exactly where the scam draws its force. The attackers invent no overdue payment and no frozen account. They pick up the one worry that every hardware wallet owner carries anyway. Microcontrollers from that product line sit in countless industrial devices, the term is easy to look up, and the history of cryptocurrencies does contain real randomness failures. The claim is verifiably false, yet it is not obviously absurd. Anyone who has self-custodied Bitcoin for years reads a line like that with a raised pulse.

SPF, DKIM and DMARC: What These Three Checks Prove and What They Do Not

Modern mail clients test every incoming message against three mechanisms. SPF (Sender Policy Framework) publishes, in the domain, a list of the servers allowed to send on its behalf. DKIM (DomainKeys Identified Mail) attaches to every message a cryptographic signature belonging to the domain. DMARC ties both results together and tells the recipient what should happen when one of them fails.

The site Cryptopolitan quotes a recipient whose copy of the warning mail passed all three checks. That is neither a contradiction nor a failure of the technology. It follows from what these mechanisms actually guarantee. What they establish is that a message travelled through a server the domain owner has authorised for the purpose. About the author of the text, the three checks say nothing.

A company that sends newsletters and service mail will as a rule authorise a specialist delivery provider for the job. If attackers gain access to that provider's interface, they send from the authorised channel. SPF matches, DKIM signs, DMARC reports green. The green tick in the mail client confirms in this case exactly what it is meant to confirm, and still not a word of the message is true.

Remember the boundary in these terms: these checks secure the channel, not the content. Deriving trust in a call to action from them confuses the two.

Why a Breach at a Service Provider Still Does Not Open Your Wallet

A hardware wallet is a device that generates the private key and keeps it inside a sealed chip. Transactions are signed on the device; the key does not leave it, not even during signing. Attackers who break into a manufacturer's mailing provider get distribution lists, names, email addresses and, depending on what is stored there, order or delivery data. The key is not among them.

That is the good news, and at the same time the reason the attackers take the detour through email. They need you as their tool. The entire effort behind this campaign aims at a single moment: you typing your recovery phrase into a form. If that fails, the break-in at the provider was worthless to them.

In practice one calm rule follows from this. No manufacturer will ever ask you to enter, upload, photograph or submit your word list for verification. There is no technical process that would require it. If you are only now choosing a device, or want a second one as a backup, our hardware wallet comparison is a better starting point than any link in an email.

Four Data Breaches in Thirty Days: Our Count of Our Own Coverage

cryptoticker.io compiled this analysis itself on September 10, 2026. Method: a query of our own article database through the Strapi programming interface for all German-language posts created on or after January 1, 2026, whose slug contains one of eight terms (phishing, betrug, datenleck, scam, fake, identitaets, warnung, masche). The 16 results of that query were reviewed.

Ten of them date from the past thirty days. Four cases concerned the same kind of event: customer or order data held by a crypto provider leaked at a contracted service provider. The address records of two wallet manufacturers and of a Bitcoin savings plan provider were affected; one of the cases is the address leak at a logistics provider, which we covered here. Three further posts among the ten are BaFin warnings about providers operating without a licence.

The finding is unspectacular, and important for exactly that reason: the raw material for personally tailored phishing mail is currently produced on a monthly cycle, and it is produced mostly at the firms that send, pack and ship on behalf of the crypto providers. Once you are on such a list, you stay on it.

The limits of this count belong to it. It remains open whether the same recipients appear on several lists, how many German customers were affected in each case, and how many incidents occurred that we did not report on. What is measured here is our own coverage, and not the market.

Five Sentences That Appear in No Genuine Wallet Warning

When the sender address drops out as a criterion, the content is what remains. These formulations do not occur in genuine manufacturer communication:

  • A request to enter, confirm, validate or submit your recovery phrase “for verification”.
  • A deadline of a few hours, combined with the announcement that your balance will be at risk afterwards.
  • A link that leads straight to an input form instead of to the manufacturer's home page or blog.
  • A request to install an update from a file in the mail instead of through the manufacturer's official application.
  • A salutation with your full name and delivery address, meant to create familiarity. After an address leak that no longer works as proof of authenticity; it is closer to a warning sign.

The last point reverses a habit that worked well for many years. A personal salutation used to count as an indication of authenticity, because bulk mail was impersonal. Since address records started leaking regularly, it no longer serves that purpose. How far this now goes is shown by the case of the forged security letters that arrived by post in the letterbox over the summer.

Two almost identical brass seals side by side on dark velvet, one of them with a hairline casting seam, a coin with an embossed Bitcoin symbol between them
Two seals, one difference: authenticity cannot be read off at first glance.

How to Check a Security Email in Four Minutes

The procedure is always the same, whatever the manufacturer and however genuine the mail looks.

  1. Do not click any link in the message. Not even “just to look”.
  2. Ignore the sender address completely. In this case the sender works as a signal in neither direction.
  3. Open the manufacturer's site through a bookmark you set yourself, or type the address by hand. Not through a search engine: ads placed above search terms are an attack route of their own.
  4. Look in the manufacturer's blog or status area for a notice about the alleged incident. A genuine flaw of that magnitude is published there, and not distributed by email alone.
  5. Check the company's official channel on social media. In the case described here, the all-clear stood exactly there, a few hours after the mail went out.
  6. Report the message as phishing in your mail client and delete it afterwards.

Four minutes is a generous estimate. What counts in any case is the order: you leave the mail before you decide anything.

If You Have Already Clicked: What Now Matters for the Seed Phrase

A click on its own gives nothing away. A page you have opened cannot read out your recovery phrase, because it is nowhere on your computer if you store it properly. The seed phrase is the list of usually twelve or twenty-four words from which every key in your wallet can be restored. Whoever holds it holds the balance, without ever touching the device.

The only question that matters now is therefore this: did you type those words in anywhere, upload them, or photograph them and send them off? If not, the incident is over for you. Change the password of the affected mail account anyway if you use the same combination elsewhere.

If you did, speed counts. Set up a new wallet with a new recovery phrase on a clean device and move the balances there, starting with the largest position. From the moment of entry the old wallet counts as open, permanently and irreversibly; a password or a PIN changes nothing about that. Then check every application you granted approvals to with the old address, and revoke them.

Record the process in writing, with date, time and amount. You will need that record later for a police report and for the tax treatment of a loss.

Exchange Account Instead of Wallet: Why the Same Scam Looks Different There

Anyone holding a balance at an exchange receives mail of a different kind: alleged withdrawals, account freezes or proof requests under the European crypto market regulation MiCA. The pattern is the same, the lever is another one: the target is login data and the second factor. We wrote up how to recognise that variant using the example of the forged withdrawal request.

Three settings noticeably lower the risk there, and all three are set in a few minutes. First, a withdrawal whitelist: withdrawals then go only to addresses you have registered beforehand, and new addresses take effect only after a waiting period. Second, a second factor through an authenticator app or a security key instead of SMS, because a phone number can be taken over through a SIM swap. Third, a separate email address that you use exclusively for exchange accounts and that appears in no newsletter.

Steel chain with a heavy padlock on the handle of a safe door, in front of it a coin with an embossed Bitcoin symbol
Protection is created on the route you choose yourself, and not in the inbox.

What is still open belongs to the picture as well. The security researcher Jameson Lopp and Nick Neuman, head of the custody provider Casa, consider it possible that the attack through the mailing provider hit more than one manufacturer; Neuman reports similar messages sent to customers of a second wallet provider. That is the assessment of two named experts, not a confirmed fact, and the companies concerned have so far not commented conclusively. For your own behaviour it changes nothing in any case: the procedure above applies to every mail, whoever the sender is.

Recognising a Forged Security Warning: What You Take Away

  1. Set a bookmark to your wallet manufacturer's site today and use only that one in future. If you find in the process that you want to replace your device or add a second one, compare the models in the hardware wallet comparison instead of through a link from your inbox.
  2. Activate the withdrawal whitelist and an app-based second factor on every exchange account. Which trading venues offer these settings and operate under European supervision is shown in the overview of regulated crypto exchanges.
  3. Decide where your recovery phrase is kept, and leave that place unchanged. The word list belongs on paper or metal, never in a file, never in a form. If you hold amounts on your computer, you should also check which application is suitable for that, for instance in the software wallet comparison.

The attackers proved this week that they can use a manufacturer's genuine letterbox. What they cannot do: take the words out of your safe. That part you decide.

Sources: Trezor statement on X of September 9, 2026; Decrypt of September 9, 2026.

(As of September 10, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.

More from CryptoTicker