Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
An alleged security warning to wallet customers travelled through the manufacturer's genuine sending channel and passed every technical authenticity check. The test that still holds costs you four minutes.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
On Wednesday evening, owners of a hardware wallet found an email in their inbox with the subject line “Critical Security Alert: STM32 Entropy Vulnerability”. The message looked like a security warning from the manufacturer Trezor, and it arrived through that company's genuine sending channel. Trezor made clear the same evening that the message had not come from it. That removes the piece of advice which tops almost every guide: look at the sender address.
This article explains how to recognise a forged security warning when the technical authenticity checks in your mail client all report green, and which four minutes of work protect you from the most expensive mistake a crypto investor can make.
What Happened on September 9: A Warning Email Through the Genuine Channel
Trezor said on its account on X on September 9, 2026: “Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link.” According to Decrypt, the post went live at around 4:30 pm US Eastern time, shortly after 10:30 pm in Germany. Recipients had already been reporting the message for hours.
What sets this apart from the usual forgeries is the route the mail took. The Block reports that the messages were sent through the company's legitimate official domain; the target of the attack was an external service provider that the manufacturer uses to send customer mail. Trezor has not publicly named the provider. The company had the linked landing page taken down and announced an investigation. By its own account, the wallet itself was never affected.
For you as a recipient, that means the mail sat in your inbox among genuine messages from the same sender, with the same layout, from the same domain. No typo in the name, no clumsy translation, no suspicious attachment.
STM32 Entropy: Why the Invented Flaw Sounded So Credible
The forgery claimed that developers had found a critical hardware-level flaw in microcontrollers of the STM32 family. Roughly one device in four was affected, the mail said, and the fault weakened the randomness of the recovery phrase. That is how Decrypt describes the content of the message.
Entropy is the cryptographic term for the amount of randomness a key is generated from. The less randomness goes into that step, the smaller the space of possible keys becomes, and the easier one of them is to guess. A genuine entropy weakness would be the gravest finding imaginable for a wallet, because it hits every device in the same production run and not just a single account.
That is exactly where the scam draws its force. The attackers invent no overdue payment and no frozen account. They pick up the one worry that every hardware wallet owner carries anyway. Microcontrollers from that product line sit in countless industrial devices, the term is easy to look up, and the history of cryptocurrencies does contain real randomness failures. The claim is verifiably false, yet it is not obviously absurd. Anyone who has self-custodied Bitcoin for years reads a line like that with a raised pulse.
SPF, DKIM and DMARC: What These Three Checks Prove and What They Do Not
Modern mail clients test every incoming message against three mechanisms. SPF (Sender Policy Framework) publishes, in the domain, a list of the servers allowed to send on its behalf. DKIM (DomainKeys Identified Mail) attaches to every message a cryptographic signature belonging to the domain. DMARC ties both results together and tells the recipient what should happen when one of them fails.
The site Cryptopolitan quotes a recipient whose copy of the warning mail passed all three checks. That is neither a contradiction nor a failure of the technology. It follows from what these mechanisms actually guarantee. What they establish is that a message travelled through a server the domain owner has authorised for the purpose. About the author of the text, the three checks say nothing.
A company that sends newsletters and service mail will as a rule authorise a specialist delivery provider for the job. If attackers gain access to that provider's interface, they send from the authorised channel. SPF matches, DKIM signs, DMARC reports green. The green tick in the mail client confirms in this case exactly what it is meant to confirm, and still not a word of the message is true.
Remember the boundary in these terms: these checks secure the channel, not the content. Deriving trust in a call to action from them confuses the two.
Hardware Wallets ComparedWhy a Breach at a Service Provider Still Does Not Open Your Wallet
A hardware wallet is a device that generates the private key and keeps it inside a sealed chip. Transactions are signed on the device; the key does not leave it, not even during signing. Attackers who break into a manufacturer's mailing provider get distribution lists, names, email addresses and, depending on what is stored there, order or delivery data. The key is not among them.
That is the good news, and at the same time the reason the attackers take the detour through email. They need you as their tool. The entire effort behind this campaign aims at a single moment: you typing your recovery phrase into a form. If that fails, the break-in at the provider was worthless to them.
In practice one calm rule follows from this. No manufacturer will ever ask you to enter, upload, photograph or submit your word list for verification. There is no technical process that would require it. If you are only now choosing a device, or want a second one as a backup, our hardware wallet comparison is a better starting point than any link in an email.
Four Data Breaches in Thirty Days: Our Count of Our Own Coverage
cryptoticker.io compiled this analysis itself on September 10, 2026. Method: a query of our own article database through the Strapi programming interface for all German-language posts created on or after January 1, 2026, whose slug contains one of eight terms (phishing, betrug, datenleck, scam, fake, identitaets, warnung, masche). The 16 results of that query were reviewed.
Ten of them date from the past thirty days. Four cases concerned the same kind of event: customer or order data held by a crypto provider leaked at a contracted service provider. The address records of two wallet manufacturers and of a Bitcoin savings plan provider were affected; one of the cases is the address leak at a logistics provider, which we covered here. Three further posts among the ten are BaFin warnings about providers operating without a licence.
The finding is unspectacular, and important for exactly that reason: the raw material for personally tailored phishing mail is currently produced on a monthly cycle, and it is produced mostly at the firms that send, pack and ship on behalf of the crypto providers. Once you are on such a list, you stay on it.
The limits of this count belong to it. It remains open whether the same recipients appear on several lists, how many German customers were affected in each case, and how many incidents occurred that we did not report on. What is measured here is our own coverage, and not the market.
Five Sentences That Appear in No Genuine Wallet Warning
When the sender address drops out as a criterion, the content is what remains. These formulations do not occur in genuine manufacturer communication:
- A request to enter, confirm, validate or submit your recovery phrase “for verification”.
- A deadline of a few hours, combined with the announcement that your balance will be at risk afterwards.
- A link that leads straight to an input form instead of to the manufacturer's home page or blog.
- A request to install an update from a file in the mail instead of through the manufacturer's official application.
- A salutation with your full name and delivery address, meant to create familiarity. After an address leak that no longer works as proof of authenticity; it is closer to a warning sign.
The last point reverses a habit that worked well for many years. A personal salutation used to count as an indication of authenticity, because bulk mail was impersonal. Since address records started leaking regularly, it no longer serves that purpose. How far this now goes is shown by the case of the forged security letters that arrived by post in the letterbox over the summer.

How to Check a Security Email in Four Minutes
The procedure is always the same, whatever the manufacturer and however genuine the mail looks.
- Do not click any link in the message. Not even “just to look”.
- Ignore the sender address completely. In this case the sender works as a signal in neither direction.
- Open the manufacturer's site through a bookmark you set yourself, or type the address by hand. Not through a search engine: ads placed above search terms are an attack route of their own.
- Look in the manufacturer's blog or status area for a notice about the alleged incident. A genuine flaw of that magnitude is published there, and not distributed by email alone.
- Check the company's official channel on social media. In the case described here, the all-clear stood exactly there, a few hours after the mail went out.
- Report the message as phishing in your mail client and delete it afterwards.
Four minutes is a generous estimate. What counts in any case is the order: you leave the mail before you decide anything.
Regulated Crypto Exchanges at a GlanceIf You Have Already Clicked: What Now Matters for the Seed Phrase
A click on its own gives nothing away. A page you have opened cannot read out your recovery phrase, because it is nowhere on your computer if you store it properly. The seed phrase is the list of usually twelve or twenty-four words from which every key in your wallet can be restored. Whoever holds it holds the balance, without ever touching the device.
The only question that matters now is therefore this: did you type those words in anywhere, upload them, or photograph them and send them off? If not, the incident is over for you. Change the password of the affected mail account anyway if you use the same combination elsewhere.
If you did, speed counts. Set up a new wallet with a new recovery phrase on a clean device and move the balances there, starting with the largest position. From the moment of entry the old wallet counts as open, permanently and irreversibly; a password or a PIN changes nothing about that. Then check every application you granted approvals to with the old address, and revoke them.
Record the process in writing, with date, time and amount. You will need that record later for a police report and for the tax treatment of a loss.
Exchange Account Instead of Wallet: Why the Same Scam Looks Different There
Anyone holding a balance at an exchange receives mail of a different kind: alleged withdrawals, account freezes or proof requests under the European crypto market regulation MiCA. The pattern is the same, the lever is another one: the target is login data and the second factor. We wrote up how to recognise that variant using the example of the forged withdrawal request.
Three settings noticeably lower the risk there, and all three are set in a few minutes. First, a withdrawal whitelist: withdrawals then go only to addresses you have registered beforehand, and new addresses take effect only after a waiting period. Second, a second factor through an authenticator app or a security key instead of SMS, because a phone number can be taken over through a SIM swap. Third, a separate email address that you use exclusively for exchange accounts and that appears in no newsletter.

What is still open belongs to the picture as well. The security researcher Jameson Lopp and Nick Neuman, head of the custody provider Casa, consider it possible that the attack through the mailing provider hit more than one manufacturer; Neuman reports similar messages sent to customers of a second wallet provider. That is the assessment of two named experts, not a confirmed fact, and the companies concerned have so far not commented conclusively. For your own behaviour it changes nothing in any case: the procedure above applies to every mail, whoever the sender is.
Recognising a Forged Security Warning: What You Take Away
- Set a bookmark to your wallet manufacturer's site today and use only that one in future. If you find in the process that you want to replace your device or add a second one, compare the models in the hardware wallet comparison instead of through a link from your inbox.
- Activate the withdrawal whitelist and an app-based second factor on every exchange account. Which trading venues offer these settings and operate under European supervision is shown in the overview of regulated crypto exchanges.
- Decide where your recovery phrase is kept, and leave that place unchanged. The word list belongs on paper or metal, never in a file, never in a form. If you hold amounts on your computer, you should also check which application is suitable for that, for instance in the software wallet comparison.
The attackers proved this week that they can use a manufacturer's genuine letterbox. What they cannot do: take the words out of your safe. That part you decide.
Sources: Trezor statement on X of September 9, 2026; Decrypt of September 9, 2026.
(As of September 10, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
- Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
- Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
- SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
- Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
September 15, 2026 3:53 PM

Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now
Waltio has told users its Brevo account was accessed during the September breach that also hit Trezor and BitBox. Here is what was exposed.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
August 23, 2026 4:36 PM

Operation ASTERIX: How a Fake Support Call Delivers a Counterfeit Wallet App
Security researchers analysed an open server on which a phone system, phishing interfaces and cloned wallet programs all came together. The largest list of numbers was the German one.
December 22, 2020 3:49 PM

Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
Ledger, a cryptocurrency wallet provider has encountered a data breach. The official Twitter account of the hardware wallet tweeted that they have been alerted to the dump of a client database.
December 28, 2018 3:02 PM

How To Use a Trezor Wallet?
Trezor is a hardware wallet which gives exceptional security for managing Bitcoin and other cryptocurrencies private keys.It incorporates and deposits personal keys securely and enables users to carry trade without an Internet link. Trezor grants its users with numerous benefits, […]
August 22, 2026 10:29 AM

Bitcoin Fork: What Happens to Your Coins When the Chain Splits
On October 31, 2026 a new chain called ECX splits off from Bitcoin, and every holder is credited automatically. Who actually receives the coins depends on the private keys, on voluntary replay protection and on a tax rule many overlook.
August 21, 2026 7:26 PM

Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
Your seed is yours; the device belongs to a company. This article explains what the open BIP39 standard actually guarantees, why a wrong derivation path makes a full wallet look empty, and the test that settles both in twenty minutes.
August 4, 2026 1:21 PM

Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
A fourth wave of Coldcard sweeps took another 449 BTC on Monday, yet Bitcoin climbed back toward $64,000. Here is what changed and who is still exposed.
September 13, 2026 10:19 PM

Reporting Duty for Wallet Makers: What Has Applied Since September 11, 2026
Since September 11, 2026, anyone offering a wallet commercially in the EU must report an actively exploited vulnerability within 24 hours and inform the affected users. What Article 14 of the EU Cyber Resilience Act requires, where the limit of interpretation lies, and what you should take from it for your own custody.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 22, 2026 4:34 PM

BitBox02: Firmware 9.26.5 Closes Three Security Vulnerabilities. What to Check Now
BitBox released firmware 9.26.5 on August 17, 2026, closing three security vulnerabilities in the BitBox02 and BitBox02 Nova. Existing seeds are not affected according to the manufacturer; an update is due anyway, and with unused devices the order matters.
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
September 1, 2026 7:27 AM

Clipboard Attack: How Malware Swaps the Wallet Address You Copied
A clipper replaces the receiving address between copying and pasting with the attacker’s, and your wallet’s checksum notices nothing. What Microsoft and the Federal Office for Cybersecurity have documented, and which check really makes the attack come to nothing.
August 31, 2026 1:22 PM

Cosmostation Wallet Shutdown on September 1: What Cosmos Wallet Users Should Know Now the Deadline Has Passed
Recap as of September 27, 2026: Cosmostation had announced it would discontinue its wallet apps on September 1, 2026, leaving only the export of the recovery phrase and the private key. This article describes the situation before the deadline and how to move Cosmos holdings, including delegated ATOM.
April 27, 2026 10:30 AM

Win $5,000 in BTC: Tangem Launches Exclusive 2026 Prize Draw
Tangem announces a massive prize draw with $5,000 in BTC and iPhone 17s up for grabs. Secure your crypto and enter today using our exclusive link.
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
September 19, 2026 1:23 AM

Hardware wallet lost: how to rescue your coins and what the tax office accepts
Your hardware wallet is gone, your coins are still on the blockchain: all that matters is whether you still have your recovery phrase. What goes wrong during a restore, and why the tax office as a rule does not recognise permanently lost access as a loss under Section 23 of the Income Tax Act.
More from CryptoTicker
