Overview
- Trezor said Wednesday that a third-party email provider it uses was breached and that attackers sent a phishing message titled "Critical Security Alert: STM32 Entropy Vulnerability" from a legitimate Trezor domain.
- BitBox and several other hardware wallet firms reported similar emails, and security researchers say the pattern points to a likely compromise of a shared newsletter or marketing provider.
- Trezor has taken down the affected domain and opened an investigation into how the attackers gained access; officials say the company has not reported any loss of cryptocurrency tied to the campaign so far.
- The fake alert played on recent real-world fears about weak random number generation by claiming an STM32 microcontroller entropy flaw that could expose recovery phrases, increasing the chance users would follow malicious links.
- This attack follows an August ShipMonk breach that exposed roughly 81,000 Trezor customer records, a combination experts say makes phishing more credible and highlights repeated third-party supply‑chain risk for wallet ecosystems.