Key Takeaways
- A security breach at Trezor’s third-party email service enabled cybercriminals to distribute phishing messages using the company’s legitimate domain
- The fraudulent message referenced a fictitious “STM32 Entropy Vulnerability” and instructed recipients to upgrade their hardware wallets
- BitBox wallet owners were hit with comparable phishing attempts, indicating a potentially broader compromise affecting multiple hardware wallet companies’ email infrastructure
- Trezor deactivated the affected domain and initiated a security investigation
- The incident comes after a ShipMonk logistics breach last month that compromised personal information of more than 80,000 Trezor users
On Wednesday, Trezor publicly acknowledged that cybercriminals had gained unauthorized access to its third-party email service provider. The breach enabled attackers to distribute phishing emails that appeared to originate from an authentic Trezor email address.
The fraudulent message carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” It falsely alleged that a hardware defect in Trezor products could compromise the randomness of seed phrases, thereby threatening user assets.
Trezor responded immediately via its X account. “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” the hardware wallet manufacturer stated.
According to the company, it has disabled the compromised domain and initiated a forensic investigation to determine exactly how attackers obtained unauthorized access.
Security analysts believe the message was strategically designed to capitalize on user anxiety following the recent Coldcard security flaw, which resulted in Bitcoin losses exceeding $130 million.
BitBox Users Also Under Attack
Switzerland-based hardware wallet company BitBox disclosed that its customers received comparable phishing emails on the identical day. The development suggests the security incident may affect multiple hardware wallet providers simultaneously.
Nick Neuman, CEO of Casa, suggested on X that a common email marketing platform was probably compromised. “Stay frosty and don’t trust provider emails that try to get you to take actions via sketchy looking links,” he cautioned.
Jameson Lopp, who serves as Casa’s Chief Security Officer, reinforced these warnings. He indicated that malicious actors may have penetrated email service providers utilized by both Trezor and BitBox, emphasizing that these messages were genuinely sent from legitimate addresses rather than being spoofed.
Cryptocurrency analyst MHPaz published screenshots of the phishing email, verifying it displayed official domain names and digital signatures that appeared completely legitimate.
Repeated Security Incidents
This represents the latest in a series of recent security challenges affecting Trezor. In the previous month, a data breach at logistics partner ShipMonk resulted in the exposure of personal information for 80,689 customers, including full names, email addresses, telephone numbers, and physical mailing addresses.
At that time, Trezor cautioned that the compromised information could facilitate more sophisticated targeted phishing operations. Current events appear to validate those concerns.
Additionally, in June, Ledger’s security researchers revealed a laboratory-identified hardware vulnerability affecting the TROPIC01 chip incorporated in the Trezor Safe 7 device. Trezor maintained that the discovery presented no actual risk to user assets.
Hardware wallet owners are strongly encouraged to avoid clicking any links contained in security-focused emails from wallet manufacturers until additional information becomes available. All alerts should be independently confirmed by visiting the official company website directly.
To date, no confirmed asset losses have been attributed to this ongoing phishing operation.





