The fake alert claimed an STM32 entropy flaw in about one in four devices, a lure that lands harder six weeks after a real entropy bug drained 594 bitcoin from Coldcard wallets. BitBox users received near-identical mail the same day.
Trezor told customers on September 9 that an email arriving from its own domain was not from Trezor. The hardware wallet maker said a third-party email provider it uses had been breached, and that a message titled “Critical Security Alert: STM32 Entropy Vulnerability” had gone out through it.
“Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link,” the company wrote on X. Decrypt places the post after 4:30 p.m. Eastern time. Trezor said it had taken down the domain the email pointed to and opened an investigation. It has not named the provider that was compromised, and it has not said how many customers received the message.
The lure was chosen well. According to Decrypt's description of the email, it claimed engineers had found a flaw in the STM32 microcontrollers inside roughly one in four Trezor devices, and that affected units may have generated recovery phrases with too little randomness. Entropy is the raw unpredictability a wallet draws on when it creates a seed. Weaken it and the resulting phrase stops being one of an unimaginable number of possibilities and becomes one of a set an attacker can search.
That is not a hypothetical failure. In late July a genuine entropy bug did exactly that to a rival product. A 2021 firmware defect on Coldcard Mk3 devices degraded seed generation, and an attacker who worked out the weakness swept 594 bitcoin from about 500 wallets in 25 minutes. A Trezor owner who followed that story in July and then received mail from Trezor's own domain in September, warning about entropy, had little in the headers to tell them apart.
Trezor was not the only vendor targeted. BitBox, the Swiss hardware wallet maker, warned the same day that a phishing email was circulating in its name. “There is currently a phishing email going around that's pretending to come from us. Please do not follow the instructions in the email!” the company said, in remarks reported by crypto.news. BitBox added that its early reading pointed at its newsletter provider, and that several bitcoin companies appeared to have been reached through the same third-party service. That is a preliminary finding rather than a confirmed one, and neither company has published a shared conclusion or named the service. Casa chief executive Nick Neuman and Jameson Lopp both flagged the BitBox messages, Decrypt reported.
Neither vendor has reported that recovery phrases or customer funds were touched, and nothing in either disclosure suggests the devices themselves were involved. A mailing list is not a wallet. What a breached email provider hands an attacker is a list of confirmed hardware wallet owners and a trusted envelope to reach them in, which is the whole of what a phishing campaign needs.
Trezor's customer data has now been exposed through somebody else's system twice inside a month. In August the company disclosed that a flaw in Metabase, an analytics tool used by its shipping partner ShipMonk, gave attackers 90 days of order data, including full names, phone numbers and shipping addresses. MiningPool reported 13,689 affected buyers at the time. Later accounts put the total higher: The Block describes the disclosure widening to about 67,000 US customers, and Decrypt gives the figure as 80,689. Trezor has not published a single reconciled number. Names and addresses of people known to own a hardware wallet are the raw material for precisely the campaign that arrived on September 9.
The pattern across the summer is that the devices have held up better than the software and services arranged around them. Ledger patched a race condition in its Ethereum app that could show one transaction on screen and sign another. The Coldcard losses came from firmware shipped five years ago. This week's incidents did not involve wallet code at all, only the mailing infrastructure two vendors rent from other companies.
The defense has not changed. No hardware wallet vendor asks for a recovery phrase, and a legitimate firmware notice does not arrive as a link in an email. Trezor's instruction was to click nothing in the message. The usual first check, whether the sender domain is real, is the one that failed here.