Trezor Warns of Phishing Emails Sent Through Hacked Email Provider
Bitcoin hardware wallet maker Trezor has warned customers that hackers breached its third-party email provider and used it to send a phishing email disguised as an urgent security notice. The fraudulent message, titled 'Critical Security Alert: STM32 Entropy Vulnerability,' falsely claimed Trezor engineers had found a hardware flaw affecting one in four devices that could weaken the randomness used to generate recovery phrases. Trezor confirmed on social media that the email did not come from the company, took down the malicious domain involved, and is investigating how attackers gained access.
Because the emails passed authentication checks and appeared to come from a legitimate Trezor address, several users were initially fooled. Security researchers, including Casa's Nick Neuman and Jameson Lopp, said the campaign may not be limited to Trezor, with reports that BitBox customers received similar fake alerts. They believe a shared marketing email provider may have been the point of compromise, and stressed that no genuine security advisory matching the email's claims had been issued.
The incident follows a similar phishing wave in August that exploited fears stemming from real vulnerabilities disclosed in Coldcard hardware wallets, showing attackers are increasingly capitalising on genuine security news to make scams more convincing.