Key Takeaways
- Cybercriminals compromised Trezor’s email service provider, enabling them to distribute phishing messages from the company’s legitimate domain
- Recipients received fraudulent alerts about an alleged “STM32 Entropy Vulnerability” prompting immediate device updates
- A parallel phishing campaign targeted BitBox wallet owners, indicating a broader attack on hardware wallet email infrastructure
- Trezor has disabled the compromised domain and initiated a security investigation
- The incident comes on the heels of last month’s ShipMonk breach that compromised information for more than 80,000 Trezor clients
On Wednesday, Trezor publicly acknowledged that cybercriminals had successfully infiltrated its third-party email service provider. The breach enabled attackers to distribute phishing messages that appeared to originate from an authentic Trezor email address.
The fraudulent message bore the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” It falsely asserted that a hardware defect in Trezor wallets could compromise the randomness of recovery seed phrases, thereby jeopardizing user assets.
Trezor responded swiftly via its X account, stating: “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”
According to the company’s statement, the malicious domain has been deactivated while security teams work to determine exactly how unauthorized access was obtained.
The timing of the fraudulent email suggests attackers deliberately capitalized on recent anxiety surrounding the Coldcard security flaw, which resulted in losses exceeding $130 million in Bitcoin.
BitBox Users Face Similar Threats
On the same day, Switzerland-based hardware wallet manufacturer BitBox disclosed that its customer base had also received comparable phishing communications. This development suggests the security incident may extend beyond Trezor’s infrastructure.
Casa’s Chief Executive Officer, Nick Neuman, commented on X that the evidence points to a compromise of a common email marketing platform. “Stay frosty and don’t trust provider emails that try to get you to take actions via sketchy looking links,” he cautioned.
Jameson Lopp, who serves as Chief Security Officer at Casa, reinforced these warnings. He emphasized that malicious actors likely penetrated email service providers utilized by multiple hardware wallet companies, noting that the messages weren’t spoofed but originated from genuine addresses.
Cryptocurrency analyst MHPaz published screenshots of the deceptive email, verifying that it displayed official domain credentials and digital signatures that appeared legitimate.
Recurring Security Challenges
Trezor’s recent security history includes multiple incidents. In the previous month, logistics partner ShipMonk suffered a data breach that exposed personal information of 80,689 customers, including full names, email addresses, telephone numbers, and physical mailing addresses.
At that time, Trezor cautioned that the compromised information could facilitate more sophisticated, personalized phishing operations. Current events have validated those concerns.
Earlier in June, Ledger’s security researchers identified a laboratory-verified hardware weakness in the TROPIC01 chip integrated into the Trezor Safe 7 model. Trezor maintained that the discovery posed no actual threat to customer funds.
Hardware wallet owners are currently being urged to avoid clicking embedded links in security-oriented emails from wallet manufacturers until additional clarity emerges. All alerts should be independently confirmed through official company websites.
To date, no confirmed financial losses have been attributed to this particular phishing operation.


