Trezor said its third-party email provider was breached and used to send phishing emails.
The fake alert claimed an STM32 hardware flaw weakened recovery phrases on some Trezor devices.
Security researchers said similar emails targeting BitBox users may point to a broader compromise of hardware-wallet email providers.
Hardware wallet maker Trezor warned users Wednesday that hackers breached its third-party email provider and used it to distribute a phishing email disguised as a critical security warning.
“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” Trezor wrote on X.
Myriad: How high will Bitcoin go in September? Click to make your prediction.
Trezor said it took down the domain used in the attack and is investigating how hackers gained access to its legitimate domain.
The fake Trezor email claims the company’s engineers discovered a “critical hardware-level vulnerability” in STM32 microcontrollers used in its devices. It then falsely claims the defect affects an estimated one in four devices and could leave recovery phrases with insufficient randomness, or entropy, likely playing on fears related to the recent Coldcard exploit that cost users over $130 million in Bitcoin.
Trezor issued a statement calling the email fraudulent and warning its users just after 4:30 p.m. Easter Time, but it came hours after several users reported receiving the phishing scam from what appeared to be a legitimate Trezor email address.
Casa co-founder and CEO Nick Neuman said the campaign may extend beyond Trezor, adding he’d heard the same from Bitbox users as well.
“It’s likely that a marketing email provider was compromised,” Neuman said on X. “Stay frosty and don’t trust provider emails that try to get you to take actions via sketchy looking links.”
Bitcoin security researcher and Casa Chief Security Officer, Jameson Lopp, raised a similar warning.
“Threat actors may have compromised the email provider(s) used by Trezor and BitBox,” he posted. “Malicious emails claiming both have bad RNGs that require security updates are being sent, and the emails don’t appear to be spoofed,” Lopp wrote on X. “No such security advisory has been issued!”
In August, Trezor and fellow crypto hardware wallet maker Foundation warned users about phishing attempts exploiting hardware wallet security fears after researchers disclosed vulnerabilities affecting Coldcard devices.
That same month, Trezor reported that a breach at shipping provider ShipMonk exposed customer data belonging to 80,689 people, including names, email addresses, phone numbers, and shipping addresses, and warned that the leaked information could be used in more sophisticated phishing attacks.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.