On September 9, hackers compromised a third-party email service used by Trezor and blasted out fake emails to users warning of a supposed critical vulnerability in Trezor hardware wallets. Trezor quickly alerted the community that these messages weren't legit—they're part of a phishing attack.

What Happened

Trezor reported that its external email provider had been breached. According to the company, any email with the subject line “Critical Security Alert: STM32 Entropy Vulnerability” is not official. Users were urged not to click on any links in these emails.

Phishing Email Details

Users said the emails appeared to come from “Trezor Security” with the subject “Critical Security Alert: STM32 Entropy Vulnerability.” The content was disguised as an urgent security warning to trick recipients.

Trezor’s Response

Trezor stated that the domain tied to the phishing attack has already been taken offline and an investigation is underway. The company urged users to ignore these phishing emails and avoid clicking any links they contain.