Security

Trezor Says Third-Party Email Provider Was Breached in Phishing Campaign

Trezor said its third-party email provider was breached and warned that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” is a phishing attempt, not a message from the company. In a security alert on its official blog, the hardware wallet maker said it has taken down the domain involved and is investigating how attackers gained access to its legitimate email infrastructure.

The company’s warning came after users reported receiving emails that appeared to come from Trezor. Trezor said recipients should not click any links in the message. The email subject line references a supposed STM32 entropy vulnerability, but the company said the alert itself was unauthorized.

Domain taken down as investigation continues

Trezor said it has already taken down the affected domain while it reviews how the compromise happened. The company did not say in its statement whether customer data was accessed in the incident, and it did not provide additional technical details about the breach in the alert.

The phishing message is the latest security issue to affect the hardware wallet maker’s communications channels. It follows a separate provider-related breach disclosed previously by the company, though Trezor has not connected the two incidents in its statement.

For users, the immediate concern is the authenticity of any security email claiming to come from Trezor. The company’s warning makes clear that the flagged message was not sent by its team and should be treated as malicious.