Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider

Hardware wallet maker Trezor said hackers breached a third-party email provider and used it to send a phishing message masquerading as a critical security advisory. The fraudulent email alleged an STM32 microcontroller flaw that reduced entropy in recovery phrases on some devices; Trezor says the alert was not legitimate and has taken down the domain used in the attack.

By AI NewsroomPublished 40 minutes agoUpdated 40 minutes ago0 views
Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider

Why It Matters

The campaign plays on recent hardware-vulnerability fears and follows earlier data exposures that could help attackers craft convincing scams, increasing the risk that users will be tricked into following malicious links. Similar reports involving BitBox users suggest the compromise may affect multiple wallet providers through shared email services.

Key Facts

  • company: Trezor
  • incident: Third-party email provider breached and used to send phishing emails
  • phishing-subject: "Critical Security Alert: STM32 Entropy Vulnerability"
  • claimed-impact: Email falsely asserted one in four devices were affected and that recovery phrases could have insufficient randomness
  • action-taken: Trezor took down the domain used in the attack and is investigating how the attackers accessed its domain

Trezor warned users on Wednesday that attackers had compromised a third-party email provider and used it to send a phishing message posing as an urgent security advisory. The company said the email, titled "Critical Security Alert: STM32 Entropy Vulnerability," did not come from Trezor and urged recipients not to click any links. Trezor also removed the malicious domain and said it is probing how the attackers obtained access tied to its legitimate domain.

The fraudulent message claimed Trezor engineers discovered a hardware-level defect in STM32 microcontrollers used by some devices and alleged the flaw left recovery phrases with insufficient entropy, saying roughly one in four devices were affected. The email appears designed to exploit concerns sparked by a recent Coldcard exploit, which researchers have linked to losses of over $130 million in Bitcoin.

Security figures and other wallet makers flagged signs the campaign could be broader than Trezor. Casa CEO Nick Neuman and security researcher Jameson Lopp both suggested marketing or email service providers used by multiple hardware-wallet companies may have been compromised; Neuman said he had heard similar reports from BitBox users. Both warned that the messages did not look like routine advisories and urged users not to trust links in provider emails.

The incident follows a string of related security concerns for hardware-wallet vendors. In August, Trezor and the Foundation warned about phishing that leveraged hardware-vulnerability disclosures, and Trezor disclosed a separate August breach at logistics firm ShipMonk that exposed personal data for 80,689 customers — information attackers could use to make phishing campaigns more convincing. Users are advised to treat unexpected security emails with skepticism and verify advisories directly with vendors' official channels.

Keep Reading