Fake STM32 Security Alert Sparks Phishing Wave Targeting Trezor and BitBox Users
Hardware‑wallet manufacturers Trezor and BitBox issued warnings on September 9 regarding a phishing campaign that masqueraded as a genuine security notice about an alleged STM32 entropy vulnerability.
Trezor highlighted that the message originated from a third‑party email provider that had suffered a breach, and reiterated on September 10 that no compromise had occurred to its own wallets.
The company identified an email titled “Critical Security Alert: STM32 Entropy Vulnerability” as a deceptive attempt to mimic a real threat. It instructed anyone who received it to disregard the attached hyperlinks and avoid any further interaction.
On September 9 Trezor also announced that the malicious domain had been taken offline and was under investigation to determine how attackers gained access to what is now a legitimate domain name.
By the following day, Trezor confirmed that its hardware devices remained secure and repeated the assessment that the breach involved only a third‑party email service provider.
BitBox issued parallel admonitions on September 9, telling affected users to refrain from acting on phishing instructions while it continued its forensic review.
A subsequent update indicated that BitBox’s preliminary examination suggested its newsletter distribution platform may also have been compromised.
The firm noted that several Bitcoin‑related entities had similarly been targeted, potentially via the compromised newsletter service. BitBox had already alerted all subscribers, reported the phishing domains to the provider, and emphasized the importance of verifying any claims directly with official sources.
Most of the malicious links referenced by victims were removed shortly before the final updates, though BitBox warned that its ongoing investigation had not concluded fully.
Individuals receiving such messages were advised to disregard any calls to action embedded in the emails, treat recovery seed phrases with utmost secrecy, and confirm any concerns solely through verified channels operated directly by Trezor and BitBox.
The signal, before the noise.
Whoops, looks like there was a problem. Please try again.
You’re on the list. Your next Daily Brief is on its way.
Protecting Recovery Seeds Remains Priority
The phishing campaigns used spoofed emails to trick individuals into revealing sensitive information or performing unauthorized actions. While Trezor affirmed that its core software and hardware remain uncompromised, it reinforced the critical recommendation to protect recovery seeds—often referred to as backup words or mnemonic phrases—with extreme care.
“Never share your recovery seed,” Trezor emphasized. “If you lose access to your device, that phrase is your only lifeline.” Its security policy consistently urges users to verify any inquiry directly with the vendor’s official support channels rather than responding to unsolicited communications.
Similarly, BitBox stressed that following deceptive links on purported security alerts can expose user funds. Its guidance advises users to download Trezor Suite exclusively from the manufacturer’s official site and to exercise caution when engaging with unexpected marketing emails.
Key takeaways for consumers:
- Do not click links in unsolicited security notifications.
- Treat recovery seed phrases as nuclear‑level secrets; never transmit them via email or chat.
- Verify the authenticity of alerts through official websites.
- Report phishing attempts to relevant CISO or security teams.
SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft
SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft


