Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.




Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
If a message titled "Critical Security Alert: STM32 Entropy Vulnerability" landed in your inbox this week, apparently from Trezor, telling you that one in four devices shipped with a defective chip and inviting you to run an entropy check in your browser, stop. Do not click anything in it. Trezor did not send it.
The company confirmed on Wednesday that attackers had gotten into its email infrastructure and used it to blast a fake security warning to customers. The email is a seed harvester dressed up as an apology, and it is one of the more convincing phishing attempts the hardware wallet space has seen in years.

What Does the Fake Trezor Security Alert Actually Claim?
The email opens with the tone of a company confessing to a disaster. It claims Trezor's engineering team found a hardware-level defect in the STM32 microcontrollers inside its devices, that the flaw was baked in at the factory, and that roughly one device in four is affected. It says the bug produces recovery phrases with as little as 40 bits of entropy, leaving seeds open to brute-force cracking.
It then does something clever. It tells the reader never to enter a recovery phrase on a website or share it with anyone. Two paragraphs later, it invites that same reader to click a link and run an "entropy check tool" that verifies BIP-39 checksums across 12, 18 and 24-word phrases, validates SLIP-39 shares, and exports extended public keys.
That contradiction is the entire scam. The warning buys credibility, then the tool collects exactly what the warning told you to protect. Anyone who works through that checker hands over enough material to drain their wallet, and in the case of an xpub export, hands over a full map of their addresses and balances even without the seed.
Why Did Trezor Users Fall For The STM32 Story?
Because a nearly identical bug was real six weeks ago, just at a different company.
Starting on 30 July 2026, attackers exploited a firmware flaw in Coinkite's Coldcard wallets. A regression shipped in March 2021 caused affected devices to generate seed phrases using a weak software randomness source instead of the hardware random number generator, cutting effective entropy from around 128 bits to as low as 40 bits on some models. Attackers drained roughly 1,816 BTC, close to 116 million dollars, from more than 5,200 addresses across four waves. Later tallies pushed the figure past 130 million dollars.
Read that against the phishing email again. Forty bits of entropy. Seeds generated before a cutoff date. Brute-force exposure. Migrate to a new seed. The scammers did not invent a threat model. They copied a documented one, swapped the brand name, and sent it to a customer list that had spent August reading about exactly this failure mode. That is why it worked on people who normally spot phishing at a glance.
How Did The Phishing Email Come From A Real Trezor Address?
This is the part that stripped away the usual defences. The message did not arrive from a lookalike domain with a swapped character. It arrived through Trezor's own legitimate sending infrastructure after attackers compromised a third-party email provider.
Trezor said it took down the domain used in the attack and is investigating how the attackers gained access to its legitimate domain. The company has said wallets, private keys and recovery backups stored on devices were never exposed. The compromise sat in the marketing pipeline, not the product.
Hardware wallets compared: keep your seed offlineThe problem may be wider than one brand. Casa co-founder Nick Neuman said he had heard of the same campaign hitting Bitbox users and suggested a shared marketing email provider had been compromised.
What Should Trezor Owners Do Right Now?
If you only opened and read the email, nothing has happened to your funds. Delete it and move on.
If you clicked the link and entered any portion of your recovery phrase, a SLIP-39 share, or your device PIN into that page, treat the seed as burned. Generate a fresh seed on a device you trust and move everything to the new addresses immediately. Do not wait to see whether anything happens, and do not reuse the old backup for anything.
If you exported an extended public key, your funds are not directly at risk, but the attacker can now watch your balances and link your addresses. That makes you a target for follow-up scams, including phone calls and physical letters, both of which Trezor customers have already reported this year.
Going forward, the rule is unchanged and it is the only rule that matters. No legitimate wallet manufacturer will ever ask you to type your recovery phrase into a browser, for any reason, including a check that claims to protect you. Verify announcements on trezor.io or the verified Trezor account on X, and treat unexpected email as hostile regardless of what address it appears to come from.
Software wallets compared: pick one you can trustIs This Part Of A Bigger Pattern In 2026?
It is, and the pattern is not about broken devices.
This is the third failure at a Trezor vendor in four weeks. An August incident at ShipMonk, the partner handling Trezor order fulfilment, pushed the number of exposed customers above 80,000 by early September, leaking names, phone numbers and home addresses. Trezor had already warned 66,000 users after a support portal breach in 2024, and rival SafePal leaked close to 40,000 records last month.
The hardware keeps holding. The companies sitting around the hardware, holding customer contact details, keep leaking. Combine a leaked customer list with a compromised sending domain and a real vulnerability at a competitor, and you get a phishing email that reads like the genuine article.
For anyone holding coins on a hardware wallet, the practical takeaway is that your device being secure and your data being secure are now two separate questions, and only one of them is in your hands.
Related articles
- Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
- Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
- Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
- Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
- Trezor Data Breach Exposes 13,689 Customers: Names, Phone Numbers and Home Addresses Leaked
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
August 22, 2026 4:13 AM

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 15, 2026 3:53 PM

Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now
Waltio has told users its Brevo account was accessed during the September breach that also hit Trezor and BitBox. Here is what was exposed.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
December 22, 2020 3:49 PM

Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
Ledger, a cryptocurrency wallet provider has encountered a data breach. The official Twitter account of the hardware wallet tweeted that they have been alerted to the dump of a client database.
April 21, 2026 2:00 PM

LayerZero Security Alert: Is Your Crypto Safe After the $292M KelpDAO Exploit?
A $292M exploit on KelpDAO exposes a massive LayerZero vulnerability. With 47% of apps at risk, are your assets still safe in the crypto space?
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 23, 2026 10:15 AM

Coldcard 5.6.1 Is Here: Why the Update Will Not Rescue Your Old Seed
Coinkite shipped Coldcard firmware 5.6.1 and 1.5.1Q on August 20, 2026. The update closes the gap for new seeds but does not repair a seed already affected.
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
August 23, 2026 4:36 PM

Operation ASTERIX: How a Fake Support Call Delivers a Counterfeit Wallet App
Security researchers analysed an open server on which a phone system, phishing interfaces and cloned wallet programs all came together. The largest list of numbers was the German one.
December 28, 2018 3:02 PM

How To Use a Trezor Wallet?
Trezor is a hardware wallet which gives exceptional security for managing Bitcoin and other cryptocurrencies private keys.It incorporates and deposits personal keys securely and enables users to carry trade without an Internet link. Trezor grants its users with numerous benefits, […]
May 27, 2024 11:56 AM

Wave of Crypto Hacks and Exploits Hits Influencers and Memecoins: WATCH OUT!
A series of hacks on crypto influencers, celebrities, and a major memecoin exploit have raised serious security concerns within the cryptocurrency community. Here is what you need to watch out for!
September 19, 2026 1:23 AM

Hardware wallet lost: how to rescue your coins and what the tax office accepts
Your hardware wallet is gone, your coins are still on the blockchain: all that matters is whether you still have your recovery phrase. What goes wrong during a restore, and why the tax office as a rule does not recognise permanently lost access as a loss under Section 23 of the Income Tax Act.
August 21, 2026 7:26 PM

Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
Your seed is yours; the device belongs to a company. This article explains what the open BIP39 standard actually guarantees, why a wrong derivation path makes a full wallet look empty, and the test that settles both in twenty minutes.
April 21, 2026 11:15 AM

Breaking: Arbitrum Security Council Freezes $71M in ETH Linked to KelpDAO Exploit
The Arbitrum Security Council has frozen 30,766 ETH tied to the KelpDAO hack, sparking a fierce debate over decentralization and emergency powers in DeFi.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
September 13, 2026 10:19 PM

Reporting Duty for Wallet Makers: What Has Applied Since September 11, 2026
Since September 11, 2026, anyone offering a wallet commercially in the EU must report an actively exploited vulnerability within 24 hours and inform the affected users. What Article 14 of the EU Cyber Resilience Act requires, where the limit of interpretation lies, and what you should take from it for your own custody.
More from CryptoTicker

