Hardware wallet maker Trezor has alerted users to a sophisticated phishing campaign targeting its customer base. The company said a third-party provider was breached, leading to the distribution of fraudulent security warning emails.
The phishing message, titled "Critical Security Alert: STM32 Entropy Vulnerability," falsely claimed that STM32 microcontrollers used in Trezor devices could generate recovery phrases without sufficient randomness. According to the fabricated warning, the alleged flaw could affect as many as 25% of devices and put user funds at risk. Trezor confirmed the email was not sent by the company and urged users not to click any links in the message.
Trezor said it had taken down the fraudulent domain and was investigating how hackers accessed its legitimate infrastructure. The phishing attempt may extend beyond Trezor users, as Casa CEO and co-founder Nick Neuman noted that similar messages have surfaced among BitBox device users.
This marks the second significant security incident involving a Trezor partner in recent months. In August, the company disclosed a breach at its logistics partner ShipMonk, which compromised customer personal details including contact and delivery information. The initial disclosure indicated 13,689 affected customers, though Trezor later confirmed approximately 67,000 additional U.S. customers were impacted, bringing the total to roughly 80,689 people.
In a separate development, researchers from Ledger's Donjon team identified a potential vulnerability in the TROPIC01 chip used in Trezor's Safe 7 wallet. The researchers demonstrated that with specialized equipment and physical access to a device, an attacker could interfere with the chip during the firmware verification process using a focused 1064 nm laser. Trezor stated the finding does not pose a risk to user funds.


