Trezor warns users that third-party mailboxes have been compromised and phishing emails that fake "emergency security alerts" are spreading
On Wednesday, hardware wallet maker Trezor issued a warning that hackers had hacked into its third-party email provider and used the channel to distribute phishing emails disguised as "critical security warnings."
Trezor issued a statement on Platform X (formerly Twitter):"Please note that the email titled 'Critical Security Alert: STM32 Entropy Vulnerability' did not come from us, it was a phishing attempt. Don't click on any links."
Trezor said it had taken technical measures to shut down the domain name used in the attack and was investigating how hackers gained access to its legitimate domain name.
Fake email claims serious hardware vulnerability found
This fake Trezor email claims that the company's engineers discovered a "critical hardware-level vulnerability" in the STM32 microcontroller used in its devices. The email further falsely claimed that the flaw affected about a quarter of the equipment and could lead to insufficient randomness (i.e. entropy) in recovering mnemonic words.
The move is suspected to take advantage of user panic triggered by the recent attack on Coldcard's device, which resulted in more than US$13 million in Bitcoin losses.
Official response and industry warning
Trezo issued an official statement around 4:30 pm Easter time, refuting the email as fraud and reminding users. However, hours had passed since multiple users reported receiving phishing emails that appeared to come from Trezor's official email address.
Casa co-founder and CEO Nick Neuman pointed out that the attack may not be limited to Trezor, and said he had received similar feedback from BitBox users. He wrote on the X platform: "It is very likely that a marketing email provider was compromised. Please be vigilant and don't believe unofficial emails that try to induce you to take action through suspicious links."
Jameson Lopp, a Bitcoin security researcher and Casa's chief security officer, issued a similar warning. He posted: "Threat actors may have compromised the email providers used by Trezor and BitBox. There are currently malicious emails claiming that the two companies 'devices contain bad random number generators (RNG) and require security updates, but these emails do not appear to be forged. In fact, officials have not issued such safety recommendations!"
Review of past security incidents
In August this year, Trezor and Foundation, another cryptocurrency hardware wallet manufacturer, jointly warned users to guard against phishing attacks that took advantage of hardware wallet security anxiety, when researchers disclosed vulnerabilities affecting Coldcard devices.
In the same month, Trezor reported a data breach at its logistics provider ShipMonk, which resulted in the disclosure of personal information (including names, email addresses, phone numbers and mailing addresses) of 80,689 customers. Trezor warned at the time that the leaked information could be used in more complex phishing attacks.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC