Trezor Says Third-Party Email Provider Was Breached, Warns ‘STM32 Entropy Vulnerability’ Email Is Phishing
Summary
- Trezor said users should be cautious after phishing emails impersonating the company were sent following a security breach at a third-party email service provider.
- Trezor said emails with the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' were not sent by the company and warned users not to click the links, calling them a phishing attempt.
- The domain used in the phishing campaign has been blocked, but Trezor did not disclose whether user assets or hardware wallets were affected or the extent of any additional damage.
Forecast Trend Report by Period



Hardware wallet maker Trezor warned users to be on alert for phishing emails impersonating the company after a security breach at a third-party email service provider.
In a post on its official X account on September 9, Trezor said “a third-party email provider was compromised.” The company added that emails with the subject line “Critical Security Alert: STM32 Entropy Vulnerability” were not sent by Trezor and were part of a phishing attempt.
Trezor warned users not to click any links included in the email.
The domain used in the phishing campaign has been blocked. Trezor said it is investigating the cause of the incident, including how attackers were able to access the company’s legitimate domain.
The company did not disclose whether user assets or the hardware wallets themselves were affected, or provide further details on the extent of any additional damage.