Fake Trezor 'Security Alert' Email Is a Phishing Scam, Not a Real Bug
Trezor has confirmed that its email infrastructure was compromised this week and used to send a convincing phishing email titled 'Critical Security Alert: STM32 Entropy Vulnerability.' The message falsely claims that one in four Trezor devices shipped with a defective chip that weakens the randomness used to generate recovery phrases, and it urges recipients to run an 'entropy check tool' to verify their seed phrase.
The email is designed to look credible by first warning users never to share their recovery phrase, then contradicting itself by inviting them to enter that same phrase into a web tool. Anyone who does so risks handing attackers everything needed to drain their crypto wallet, and even exporting extended public keys alone can expose a full picture of a victim's addresses and balances.
The scam appears to borrow credibility from a genuine incident at a different company. Starting in late July 2026, attackers exploited a real firmware flaw in Coinkite's Coldcard wallets that weakened seed generation, resulting in roughly 130 million dollars stolen from thousands of addresses. Trezor says it did not send the STM32 email and customers should disregard and report it.