Skip to main content
See every side of every news story
Published loading...Updated

Trezor warns users of email provider breach, phishing attacks

Trezor said the fake alert is tied to a breached email provider and warned users not to click links in the message.

  • On Wednesday, Trezor and BitBox warned users of a phishing campaign after their shared third-party email provider was breached, with fraudulent emails falsely claiming a "Critical Security Alert: STM32 Entropy Vulnerability."
  • Preliminary investigations suggest the companies' shared newsletter provider was compromised, enabling attackers to target multiple Bitcoin businesses simultaneously while both firms investigate the unauthorized access.
  • The phishing emails directed recipients to a fraudulent domain presenting a fake "Critical Security Alert: STM32 Entropy Vulnerability" warning, prompting both companies to advise users not to click any links in the messages.
  • Trezor and BitBox took down the malicious domain and instructed users to ignore the emails, which impersonated the hardware wallet manufacturers to solicit sensitive recovery phrases under false pretenses.
  • This incident follows a Coldcard firmware vulnerability disclosed earlier this year involving weak random number generation, while Trezor recently expanded disclosures on a separate ShipMonk breach affecting more than 80,000 customers.
Insights by Ground AI

32 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BITRSS broke the news on Wednesday, September 9, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal