Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider

Summary

Trezor warned users that hackers breached a third-party email provider and sent phishing emails posing as a critical security alert. The fake message, “Critical Security Alert: STM32 Entropy Vulnerability,” falsely claimed Trezor devices had a hardware-level flaw in STM32 microcontrollers that could weaken recovery-phrase randomness. Trezor said the email is fraudulent, took down the domain used in the attack, and is investigating how the compromise happened. Reports suggested the messages may have come through a legitimate Trezor email address, and security figures warned the campaign may also target users of other wallet brands such as Bitbox. The attack appears designed to exploit recent fears about hardware-wallet security and RNG vulnerabilities. Trezor also recently faced a separate customer-data exposure from its shipping provider, increasing phishing risk.