Hardware wallet manufacturer Trezor stated that attackers infiltrated their third-party email service provider and used this to send phishing emails disguised as "critical security alerts." The company reminded users not to click on any links in the emails and said that they have taken down the domain names used in this attack, and are investigating how the attackers obtained access to their legitimate email domain names.
The forged content revolves around chip vulnerabilities.
This phishing email is titled “STM32 Entropy Vulnerability” and claims that there is a hardware-level defect in the STM32 microcontrollers used in some Trezor devices, which weakens the randomness during mnemonic phrase generation. The email also suggests that about a quarter of the devices may be affected and induces users to take subsequent actions.
Trezor Subsequently, on the X platform, it was clarified that the relevant emails were not sent by the company, nor had any such security alerts been issued. The sender information that users initially saw appeared to come from a legitimate email address belonging to Trezor, which is also one of the reasons why this attack was more deceptive.
Researchers claim that more than one entity may be affected.
Casa, co-founder and CEO, stated that he heard that BitBox users also received similar emails, indicating that the issue may affect more than just Trezor. One possibility is that the marketing email service provider that serves hardware wallet manufacturers has been compromised.
Bitcoin security researcher and the Chief Security Officer of Casa, Jameson Lopp, also issued a similar warning. He stated that the email service providers used by Trezor and BitBox may have been compromised, and the malicious emails sent by the attackers are not ordinary forged emails, but are sent through legitimate email channels.
- The subject of the fake email is “Critical Security Alert : STM32 Entropy Vulnerability”
- Trezor claims not to have issued any related security announcements.
- BitBox Users have also reported receiving similar content.
Recent rise in the risk of phishing attacks on hardware wallets
In August this year, Trezor and another hardware wallet manufacturer, Foundation, warned users about phishing activities that took advantage of concerns regarding the security of hardware wallets in the market. The background for this was that researchers had previously disclosed vulnerabilities affecting Coldcard devices, which subsequently led to heightened user awareness of device security issues.
Also in August, Trezor disclosed that a data breach by the logistics service provider ShipMonk affected 80,689 customers, with the leaked information including names, email addresses, phone numbers, and delivery addresses. The company warned at the time that this data could be used for more sophisticated targeted phishing attacks.
This incident shows that attackers are increasingly utilizing email infrastructure and external service providers to carry out social engineering attacks. For users of hardware wallets, emails related to mnemonic phrases, firmware updates, or emergency security fixes particularly require re-verification through the official website or official channels of the device manufacturers.










