Key Facts

Trezor warned that its third-party email provider was breached and that a message titled “Critical Security Alert: STM32 Entropy Vulnerability” is a phishing attempt. The company says it took down the domain involved and is investigating how attackers accessed its legitimate domain.

Technical Details

BleepingComputer reports that the phishing email claimed a hardware microcontroller issue could expose wallet seeds to brute-force cracking. This is a social-engineering lure; Trezor’s warning says the message is not from the company.

Impact & Mitigation

Do not click links in the identified message or disclose wallet recovery information. Treat unexpected Trezor security notices as suspicious, verify information through independently reached official channels, and monitor for follow-on phishing while the investigation continues.

Sources

By Allan