Hardware wallet maker Trezor confirmed today that hackers breached its third-party email provider and used it to send a phishing email through Trezor's genuine domain โ no spoofing needed, which makes this campaign more dangerous than most.
The bait: An email titled "Critical Security Alert: STM32 Entropy Vulnerability" falsely claims a hardware-level flaw affects roughly 1 in 4 Trezor devices, alleging insufficient randomness ("entropy") in recovery-phrase generation. This is a calculated lure timed to exploit fears from the real, recent Coldcard exploit that cost users over $130 million in Bitcoin โ worried owners are exactly the demographic this attack is designed to panic.
The reassurance: Trezor confirmed no wallets, private keys, or recovery backups were exposed. The only risk is if someone clicks the link and enters sensitive data on the resulting fake site.
The bigger red flag โ this is Trezor's third vendor failure in four weeks:
1๏ธโฃ Aug 10 โ Shipping partner ShipMonk breach exposed 80,689 customers' names, phones, and addresses
2๏ธโฃ Late August โ An earlier phishing wave exploiting hardware-vulnerability fears
3๏ธโฃ Now โ This email-provider breach and STM32 phishing campaign
Casa's Nick Neuman noted the campaign may not be Trezor-exclusive โ reports suggest Bitbox users received similar emails, pointing to a possibly shared, compromised marketing email vendor across multiple hardware wallet brands.
Why this matters for the whole space: 2026 is shaping up to be the worst year on record for crypto security โ 180+ documented incidents in H1 alone (a 50% jump YoY), with over $1.1 billion in losses. State-sponsored actors are increasingly leveraging AI for more convincing social engineering and deepfake-driven attacks, and vendor supply-chain compromises (rather than direct hacks) are becoming the preferred entry point.
Action items: Never click links in unexpected wallet-provider emails referencing chip flaws or "entropy." Never type a recovery phrase or device passcode into any website. Verify anything unusual directly through the company's official site โ never through an emailed link.
ๆ ขๆ ข่ฒทใๅๆนไฝๅฑใ่ฎๆ้็ซๅจไฝ ้้ใ๐
โ Humble Trader | Gemini Trading
๐ Trezor | Crypto Security Watch
[NOT FINANCIAL ADVICE, DYOR!]
Source: r/TradeVerseNetwork · by /u/robot2trade
