Particle.news
Download on the App Store

Hackers Breach Trezor Email Provider to Send Fake 'STM32 Entropy' Security Alert

The campaign lets attackers deliver highly convincing phishing from a genuine domain and could use earlier customer data leaks to enable targeted scams.

Overview

  • Trezor warned Wednesday that hackers breached a third‑party email/marketing provider and used it to send a phishing message titled “Critical Security Alert: STM32 Entropy Vulnerability.”
  • The fraudulent email falsely claimed a hardware‑level entropy flaw in STM32 chips and urged unsafe actions that could expose users’ recovery phrases.
  • Trezor said it took down the domain used to send the messages and is investigating how attackers gained access but has not named the email provider or disclosed how many customers were emailed.
  • Security researchers reported similar messages to BitBox users and said the attack likely reflects a compromise of one or more shared email providers, increasing the risk across hardware‑wallet customers.
  • The campaign compounds an earlier ShipMonk shipping‑provider breach that exposed names, emails, phone numbers and addresses for tens of thousands of customers and makes targeted phishing and physical social‑engineering more likely; users should not click links or enter their recovery seed on any website.