Trezor warns of phishing after third-party email breach cover
Back to BLAKE

Trezor warns of phishing after third-party email breach

The company disowns a fake STM32 security alert, says it took down the domain involved and is investigating.

Share this article

FacebookLinkedInXEmail
  1. Trezor has warned users about a phishing campaign after a breach at its third-party email provider. In a September 9 notice, the hardware-wallet maker identified an email carrying a supposed STM32 security warning as fraudulent and told recipients not to click its links.

  2. The subject line names an alleged entropy vulnerability, making the message look like an urgent problem with the way a wallet generates its recovery information. Trezor's notice identifies that message as a phishing attempt. The email's claim should not be treated as a verified device defect.

    The company said it had taken down the domain involved and was investigating. Its warning places the incident at an outside email provider. The notice reviewed for this article does not give a completed root-cause analysis, an affected-user count or a confirmed loss total.

    For users, the immediate instruction is narrow: do not follow the links in that alert. An urgent request to check a wallet can create pressure to act before checking who is asking. A familiar brand name in the message is not enough to establish that the request is legitimate.

    Trezor's own guidance says the wallet backup created during setup should be kept safely offline and never shared. Anyone checking the company's response should open its official website or support channels independently rather than use a link supplied by the suspicious message.

    Further coverage should turn on Trezor's investigation: how the email account was accessed, which information was exposed and what changes prevent another unauthorized mailing. Those questions remain separate from the fake hardware warning used to draw recipients in.