Trezor warns customers after email provider breach
Attackers breached Trezor’s third‑party email provider and sent a phishing alert about an “STM32 Entropy Vulnerability.” Trezor reports wallets and private keys were not exposed.
Trezor reported that attackers accessed its third‑party email provider and used a legitimate‑looking address to send a phishing message titled “Critical Security Alert: STM32 Entropy Vulnerability.” The company removed the malicious domain used in the campaign and is investigating how the messages were sent. Trezor reported that wallets, private keys and recovery backups stored on devices were not exposed.
The phishing email referenced STM32, the family of microcontroller chips used inside Trezor devices, and warned of an “entropy vulnerability.” Entropy is the randomness used to generate a wallet’s recovery phrase, the list of words that restore access to funds. Trezor and security experts say the alert could prompt owners to follow a link to a fraudulent page and enter their recovery phrase there.
Trezor described the incident as one in a series of vendor-related data exposures affecting hardware wallet companies. Earlier this year the company notified about a support portal breach that affected roughly 66,000 users. In August a shipping partner reported a breach that later raised the number of exposed customers above 80,000, disclosing names, phone numbers and addresses. Other wallet vendors have reported customer data leaks and similar phishing messages sent to their mailing lists.
Customers reported receiving scam phone calls and printed letters that appear linked to leaked contact details. Trezor removed the malicious domain tied to the phishing campaign and said it is coordinating with its email provider and other partners to investigate how the breach occurred.
Trezor posted public guidance urging users to ignore unexpected emails that mention STM32 or entropy and to avoid clicking links in such messages. The company advised never entering a recovery phrase or device passcode into a website and to treat unverified calls or letters with caution. Trezor directed users to check trezor.io and its verified account on X for official notices.
The company also advised anyone who entered a recovery phrase or backup on a linked page to move funds to a new wallet immediately. In a message to users, Trezor wrote: “Our third‑party e‑mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








