Trezor Warns Users of Phishing Email Compromising Third-Party Email Provider
Quick Look
- Trezor warned users that hackers breached its third-party email provider to send phishing emails posing as critical security alerts about an STM32 vulnerability.
- The fake emails claimed a hardware flaw affecting one in four devices and played on fears from the Coldcard exploit.
- Trezor took down the malicious domain and is investigating the breach, while Casa and BitBox users reported similar phishing attempts.
AI-generated summary
Why It Matters
In August, Trezor and Foundation warned users about phishing attempts exploiting hardware wallet security fears after researchers disclosed vulnerabilities affecting Coldcard devices, which led to over $130 million in Bitcoin losses.
Hardware wallet maker Trezor warned users Wednesday that hackers breached its third-party email provider and used it to distribute a phishing email disguised as a critical security warning.
“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” Trezor wrote on X.
Trezor said it took down the domain used in the attack and is investigating how hackers gained access to its legitimate domain.
The fake Trezor email claims the company's engineers discovered a “critical hardware-level vulnerability” in STM32 microcontrollers used in its devices. It then falsely claims the defect affects an estimated one in four devices and could leave recovery phrases with insufficient randomness, or entropy, likely playing on fears related to the recent Coldcard exploit that cost users over $130 million in Bitcoin.
Trezor issued a statement calling the email fraudulent and warning its users just after 4:30 p.m. Easter Time, but it came hours after several users reported receiving the phishing scam from what appeared to be a legitimate Trezor email address.
Casa co-founder and CEO Nick Neuman said the campaign may extend beyond Trezor, adding he’d heard the same from Bitbox users as well.
“It’s likely that a marketing email provider was compromised,” Neuman said on X. “Stay frosty and don't trust provider emails that try to get you to take actions via sketchy looking links.”
Bitcoin security researcher and Casa Chief Security Officer, Jameson Lopp, raised a similar warning.
“Threat actors may have compromised the email provider(s) used by Trezor and BitBox,” he posted. “Malicious emails claiming both have bad RNGs that require security updates are being sent, and the emails don't appear to be spoofed,” Lopp wrote on X. “No such security advisory has been issued!”
In August, Trezor and fellow crypto hardware wallet maker Foundation warned users about phishing attempts exploiting hardware wallet security fears after researchers disclosed vulnerabilities affecting Coldcard devices.
What to Watch
AI outlook — possibilities, not facts
Trezor will implement stronger email security protocols and provider vetting processes.
Likely · Within weeks
Other hardware wallet providers will audit their third-party email services for similar vulnerabilities.
Possible · Within weeks
Open Questions
- Which specific third-party email provider was compromised?
- How many users received the phishing email?
- Did any users fall victim to the phishing scam and lose funds?
- What steps is Trezor taking to secure its email provider moving forward?







