Market Incident
Public · Developing
Trezor's email provider was breached, and attackers sent fake emails from real Trezor email addresses. The fake email is titled "Critical Security Alert: STM32 Entropy Vulnerability" and claims a hardware defect in Trezor devices. Remember that wallet vendors will never ask
Trezor's email provider was breached, allowing attackers to send fake emails from genuine Trezor addresses. The fraudulent email, titled "Critical Security Alert: STM32 Entropy Vulnerability," falsely claims a hardware defect in Trezor devices. Trezor warns that wallet vendors never ask for sensitive information via email.
Published:
Updated:
What happened
Trezor, a company that makes hardware wallets for storing cryptocurrencies, reported that its third-party email provider was breached. Attackers sent phishing emails from real Trezor addresses. Trezor warned users not to click links and is still investigating.
Global impact / market context
This matters because phishing emails can trick users into revealing their recovery phrases, which are secret backup codes for wallets. If those are stolen, scammers can access and take cryptocurrency.
What to watch
- Trezor's investigation results: if they confirm how the breach happened, it could show whether user data was also exposed.
- Any further official warnings or updates from Trezor: this tells whether the threat is ongoing or resolved.
- Reports of users falling for the phishing scam: this shows how many people are affected and if the attack is spreading.
Evidence
- Protos.com — Trezor's summer of hacks continues with Brevo email breach
- X - solidintel_x — INTEL: ️ Trezor's email provider has been breached. Phishing emails titled "Critical Security Alert: STM32 Entropy Vulnerability" are going out from Trezor's legitimate domain, passing spam filters and looking real. Do not click any link and never enter your recovery seed on a
- U.Today — Trezor Users Targeted by Terrifying Phishing Attack After Third-Party Breach
- The Block — Trezor says third-party security breach led to phishing emails from legitimate domain
- X - CoinMarketCap — LATEST: Trezor says its 3rd-party email provider was breached, warning that an email titled "Critical Security Alert: STM32 Entropy Vulnerability" is a phishing attempt and not from Trezor.
- X - cointelegraph — ALERT: Trezor says its third-party email provider was breached and is still investigating, warning users not to click links in the fake "Critical Security Alert" phishing emails.
- X - wublockchain — Second-Largest Hardware Wallet Maker Trezor Warns of Phishing Email After Third-Party Email Provider Breach Trezor said its third-party email provider has been breached. The company warned that an email titled "Critical Security Alert: STM32 Entropy Vulnerability" did not come
- Decrypt — Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider
- AMBCrypto — Trezor email provider breached as fake wallet security alert spreads
- X - BSCNews — Trezor's email provider was breached, and attackers sent fake emails from real Trezor email addresses. The fake email is titled "Critical Security Alert: STM32 Entropy Vulnerability" and claims a hardware defect in Trezor devices. Remember that wallet vendors will never ask
- Incident timeline — Trezor's summer of hacks continues with Brevo email breach
- Incident timeline — INTEL: ️ Trezor's email provider has been breached. Phishing emails titled "Critical Security Alert: STM32 Entropy Vulnerability" are going out from Trezor's legitimate domain, passing spam filters and looking real. Do not click any link and never enter your recovery seed on a
- Incident timeline — Trezor Users Targeted by Terrifying Phishing Attack After Third-Party Breach
- Incident timeline — Trezor says third-party security breach led to phishing emails from legitimate domain
- Incident timeline — LATEST: Trezor says its 3rd-party email provider was breached, warning that an email titled "Critical Security Alert: STM32 Entropy Vulnerability" is a phishing attempt and not from Trezor.
- Incident timeline — ALERT: Trezor says its third-party email provider was breached and is still investigating, warning users not to click links in the fake "Critical Security Alert" phishing emails.
- Incident timeline — Second-Largest Hardware Wallet Maker Trezor Warns of Phishing Email After Third-Party Email Provider Breach Trezor said its third-party email provider has been breached. The company warned that an email titled "Critical Security Alert: STM32 Entropy Vulnerability" did not come
- Incident timeline — Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider
- Incident timeline — Trezor email provider breached as fake wallet security alert spreads
- Incident timeline — Trezor's email provider was breached, and attackers sent fake emails from real Trezor email addresses. The fake email is titled "Critical Security Alert: STM32 Entropy Vulnerability" and claims a hardware defect in Trezor devices. Remember that wallet vendors will never ask