Hardware wallet shielded from a phishing email threat

Trezor Warns Users After Email Provider Breach Fuels Convincing Phishing Attack

September 9, 2026 7:12 pm Comments

Trezor is warning hardware-wallet users not to trust a convincing security email sent through one of the company’s own third-party email providers.

The message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” was not a real Trezor advisory. It was a phishing attempt designed to turn the credibility of a familiar sender into a path toward a user’s crypto.

That distinction matters. The incident does not mean attackers cracked Trezor’s hardware wallets or discovered a flaw in their random-number generation.

It means they gained access to an email channel that customers could reasonably mistake for an official line of communication.

In its public warning, Trezor said its third-party email provider had been breached, told recipients not to click any link in the fake alert, and said it had taken down the domain involved while investigating how the attackers gained access.

Decrypt’s report on the incident underscores why this campaign is more dangerous than an ordinary spoofed message: the email came through infrastructure associated with a real provider. A polished design and a legitimate-looking sender can lower a user’s guard before the attacker ever asks for a seed phrase, wallet backup, or software update.

The fake “entropy vulnerability” framing is especially effective social engineering. Entropy is a real security concept, and hardware wallets depend on strong randomness when generating keys.

An urgent warning built around that language can sound technical enough to be credible while pushing a holder to act before checking an official source.

Casa co-founder Nick Neuman also warned that convincing phishing emails were circulating in the hardware-wallet market. His practical point is the one users should remember: a message can pass superficial authenticity checks and still be malicious when a provider account or distribution system has been compromised.

What Trezor users should do now:

Do not use any link in the “STM32 Entropy Vulnerability” email. If you need to check a security claim, open Trezor’s website or official social account independently rather than following a path supplied by the message.

Never type a wallet backup or recovery seed into a website. A legitimate hardware-wallet company does not need those words to patch a device, verify an account, or protect funds.

Anyone who obtains that backup can control the wallet without possessing the physical device.

Users who opened the message but did not click, download, connect a wallet, install software, or enter a recovery seed have far less exposure than users who followed the attacker’s instructions. Anyone who entered a seed into a site should treat that wallet as compromised and move assets using a clean device and a newly generated wallet, while avoiding any further links from the original message.

The larger lesson is uncomfortable but useful: self-custody removes some forms of counterparty risk, but it does not remove the human attack surface. The more convincing the message looks, the more important it is to slow down and verify the claim through a separate channel.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.