By Isaac • September 9, 2026 7:12 pm •
Trezor is warning hardware-wallet users not to trust a convincing security email sent through one of the company’s own third-party email providers.
The message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” was not a real Trezor advisory. It was a phishing attempt designed to turn the credibility of a familiar sender into a path toward a user’s crypto.
That distinction matters. The incident does not mean attackers cracked Trezor’s hardware wallets or discovered a flaw in their random-number generation.
It means they gained access to an email channel that customers could reasonably mistake for an official line of communication.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security
Continue reading
Join the conversation!
Please share your thoughts about this article below. We value your opinions, and would love to see you add to the discussion!