Breaking
INTLSen. John Fetterman to Appear Virtually at Republican Convention in Video Praising TrumpITUkrainian marine drone attack in Sochi: eight injured and damage to the seafrontBRPresident of the Supreme Court suspends decisions by Mendonça and Dino on the removal of PF directorsUSAutomattic Board Places Matt Mullenweg on Paid Leave of Absence Against His WillCNGauff overturns Andreeva to advance to the semi-finals of the US Open women's singles and will compete with Rybakina for the championship spotCNAsian Games Taiwan men's basketball team is hailed as a dark horse by Philippine media. Chen Yingjun leads the team to challenge JordanTRNorwegian President announced that Zelenskiy's plane was targeted with a UAV in MoldovaCRYPTO-ENTrezor Warns Users of Phishing Email Compromising Third-Party Email ProviderARLiverpool comes from behind with an opening win over Atletico Madrid in the Champions LeagueAUDrunk-driving police officer reinstated after crash during Dezi Freeman manhuntINTLSen. John Fetterman to Appear Virtually at Republican Convention in Video Praising TrumpITUkrainian marine drone attack in Sochi: eight injured and damage to the seafrontBRPresident of the Supreme Court suspends decisions by Mendonça and Dino on the removal of PF directorsUSAutomattic Board Places Matt Mullenweg on Paid Leave of Absence Against His WillCNGauff overturns Andreeva to advance to the semi-finals of the US Open women's singles and will compete with Rybakina for the championship spotCNAsian Games Taiwan men's basketball team is hailed as a dark horse by Philippine media. Chen Yingjun leads the team to challenge JordanTRNorwegian President announced that Zelenskiy's plane was targeted with a UAV in MoldovaCRYPTO-ENTrezor Warns Users of Phishing Email Compromising Third-Party Email ProviderARLiverpool comes from behind with an opening win over Atletico Madrid in the Champions LeagueAUDrunk-driving police officer reinstated after crash during Dezi Freeman manhunt
BackTrezor Warns Users of Phishing Email Compromising Third-Party Email Provider
Trezor Warns Users of Phishing Email Compromising Third-Party Email Provider
BREAKING
Decrypt26 minutes agoTech2 min read

Trezor Warns Users of Phishing Email Compromising Third-Party Email Provider

Quick Look

  • Trezor warned users that hackers breached its third-party email provider to send phishing emails posing as critical security alerts about an STM32 vulnerability.
  • The fake emails claimed a hardware flaw affecting one in four devices and played on fears from the Coldcard exploit.
  • Trezor took down the malicious domain and is investigating the breach, while Casa and BitBox users reported similar phishing attempts.

AI-generated summary

Why It Matters

In August, Trezor and Foundation warned users about phishing attempts exploiting hardware wallet security fears after researchers disclosed vulnerabilities affecting Coldcard devices, which led to over $130 million in Bitcoin losses.

Font size

Hardware wallet maker Trezor warned users Wednesday that hackers breached its third-party email provider and used it to distribute a phishing email disguised as a critical security warning.

“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” Trezor wrote on X.

Trezor said it took down the domain used in the attack and is investigating how hackers gained access to its legitimate domain.

The fake Trezor email claims the company's engineers discovered a “critical hardware-level vulnerability” in STM32 microcontrollers used in its devices. It then falsely claims the defect affects an estimated one in four devices and could leave recovery phrases with insufficient randomness, or entropy, likely playing on fears related to the recent Coldcard exploit that cost users over $130 million in Bitcoin.

Trezor issued a statement calling the email fraudulent and warning its users just after 4:30 p.m. Easter Time, but it came hours after several users reported receiving the phishing scam from what appeared to be a legitimate Trezor email address.

Casa co-founder and CEO Nick Neuman said the campaign may extend beyond Trezor, adding he’d heard the same from Bitbox users as well.

“It’s likely that a marketing email provider was compromised,” Neuman said on X. “Stay frosty and don't trust provider emails that try to get you to take actions via sketchy looking links.”

Bitcoin security researcher and Casa Chief Security Officer, Jameson Lopp, raised a similar warning.

“Threat actors may have compromised the email provider(s) used by Trezor and BitBox,” he posted. “Malicious emails claiming both have bad RNGs that require security updates are being sent, and the emails don't appear to be spoofed,” Lopp wrote on X. “No such security advisory has been issued!”

In August, Trezor and fellow crypto hardware wallet maker Foundation warned users about phishing attempts exploiting hardware wallet security fears after researchers disclosed vulnerabilities affecting Coldcard devices.

What to Watch

AI outlook — possibilities, not facts

  • Trezor will implement stronger email security protocols and provider vetting processes.

    Likely · Within weeks

  • Other hardware wallet providers will audit their third-party email services for similar vulnerabilities.

    Possible · Within weeks

Open Questions

  • Which specific third-party email provider was compromised?
  • How many users received the phishing email?
  • Did any users fall victim to the phishing scam and lose funds?
  • What steps is Trezor taking to secure its email provider moving forward?

Related Topics

This article was originally published by Decrypt.

Related Stories

Solana's Faster Block Times May Reduce Arbitrage Losses for Liquidity Providers
Developing·

Solana's Faster Block Times May Reduce Arbitrage Losses for Liquidity Providers

Solana's reduction of block slot times to 300 milliseconds, with plans for 200ms, aims to minimize arbitrage opportunities from outdated pool prices in automated market makers. Research suggests faster updates could let liquidity providers retain more value by reducing informational disadvantages, though benefits vary by pool type, fee structure, and volatility. Validator costs and network dynamics are also affected, with changes to voting frequency and leader slot durations.

CryptoSlate
2 min read
Blockstream in talks with hackers to recover $47 million in stolen Bitcoin from Liquid Network
Developing·

Blockstream in talks with hackers to recover $47 million in stolen Bitcoin from Liquid Network

Blockstream is in ongoing negotiations with hackers who exploited a flaw in Liquid Network's Elements software to withdraw approximately 4,000 BTC worth $320 million, aiming to recover the remaining 600 BTC valued at $47 million. The hackers returned 3,400 BTC on Monday but still hold 600 BTC. Liquid Network paused operations after the exploit, which involved unbacked L-BTC tokens being accepted as valid due to a transaction-level validation failure. The company confirmed no private keys were compromised and that functionary nodes were not hacked. Blockstream is preparing an emergency update to fix the vulnerability and restore network operations.

Decrypt
2 min read
More on this topictrezor