Wednesday, September 9, 2026

Key points

  • Trezor disclosed that a third-party email provider was compromised and used to distribute phishing messages.
  • A fraudulent notice alleged that an STM32 hardware flaw could weaken recovery phrases on certain devices.
  • Security researchers said similar emails sent to BitBox users may indicate a wider compromise of hardware-wallet email providers.

Hardware wallet maker Trezor warned users on Wednesday that attackers had compromised a third-party email provider and used it to distribute a phishing message disguised as an urgent security alert.

“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” Trezor said on X.

Trezor said it had taken down the domain used in the attack and was investigating how the attackers gained access to its legitimate domain.

The fraudulent email claimed that Trezor’s engineers had identified a “critical hardware-level vulnerability” in STM32 microcontrollers used in its devices. It falsely stated that the issue affected roughly one in four devices and could leave recovery phrases with insufficient randomness, or entropy. The message also appeared designed to exploit concerns surrounding the recent Coldcard exploit, which cost users more than $130 million in Bitcoin.

Trezor issued a statement calling the message fraudulent and warning users shortly after 4:30 p.m. Eastern Time, hours after several recipients reported receiving the phishing scam from an address that appeared to belong to the company.

Casa co-founder and CEO Nick Neuman said the campaign may extend beyond Trezor, adding that he had also heard reports from BitBox users.

“It’s likely that a marketing email provider was compromised,” Neuman said on X. “Stay frosty and don’t trust provider emails that try to get you to take actions via sketchy looking links.”

Bitcoin security researcher and Casa Chief Security Officer Jameson Lopp issued a similar warning.

“Threat actors may have compromised the email provider(s) used by Trezor and BitBox,” he posted. “Malicious emails claiming both have bad RNGs that require security updates are being sent, and the emails don’t appear to be spoofed,” Lopp wrote on X. “No such security advisory has been issued!”

In August, Trezor and hardware wallet maker Foundation warned users about phishing attempts that exploited concerns over hardware wallet security after researchers disclosed vulnerabilities affecting Coldcard devices.

That same month, Trezor reported that a breach at shipping provider ShipMonk exposed customer data belonging to 80,689 people, including names, email addresses, phone numbers, and shipping addresses. The company warned that the leaked information could be used to launch more sophisticated phishing attacks.

Source link

Exit mobile version