In brief
- Trezor said its third-party email provider was breached and used to send phishing emails.
- The fake alert claimed an STM32 hardware flaw weakened recovery phrases on some Trezor devices.
- Security researchers said similar emails targeting BitBox users may point to a broader compromise of hardware-wallet email providers.
Hardware wallet maker Trezor warned users Wednesday that hackers breached its third-party email provider and used it to distribute a phishing email disguised as a critical security warning.
“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” Trezor wrote on X.
Trezor said it took down the domain used in the attack and is investigating how hackers gained access to its legitimate domain.
The fake Trezor email claims the company’s engineers discovered a “critical hardware-level vulnerability” in STM32 microcontrollers used in its devices. It then falsely claims the defect affects an estimated one in four devices and could leave recovery phrases with insufficient randomness, or entropy, likely playing on fears related to the recent Coldcard exploit that cost users over $130 million in Bitcoin.
Trezor issued a statement calling the email fraudulent and warning its users just after 4:30 p.m. Easter Time, but it came hours after several users reported receiving the phishing scam from what appeared to be a legitimate Trezor email address.
Casa co-founder and CEO Nick Neuman said the campaign may extend beyond Trezor, adding he’d heard the same from Bitbox users as well.
“It’s likely that a marketing email provider was compromised,” Neuman said on X. “Stay frosty and don’t trust provider emails that try to get you to take actions via sketchy looking links.”
Bitcoin security researcher and Casa Chief Security Officer, Jameson Lopp, raised a similar warning.
“Threat actors may have compromised the email provider(s) used by Trezor and BitBox,” he posted. “Malicious emails claiming both have bad RNGs that require security updates are being sent, and the emails don’t appear to be spoofed,” Lopp wrote on X. “No such security advisory has been issued!”
In August, Trezor and fellow crypto hardware wallet maker Foundation warned users about phishing attempts exploiting hardware wallet security fears after researchers disclosed vulnerabilities affecting Coldcard devices.
That same month, Trezor reported that a breach at shipping provider ShipMonk exposed customer data belonging to 80,689 people, including names, email addresses, phone numbers, and shipping addresses, and warned that the leaked information could be used in more sophisticated phishing attacks.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.


