Unknown actors sent emails to wallet owners with the subject "Critical Security Alert: STM32 Entropy Vulnerability," masquerading as an urgent security warning. The email claimed that Trezor engineers had discovered a serious vulnerability in the STM32 microcontrollers used in the company’s devices. According to the message, this flaw affects every fourth device and could lead to entropy issues—where numerous predictable patterns arise during seed phrase generation, allowing an attacker to more easily guess the secret phrase.
Trezor stated that it did not send these emails, calling the campaign a targeted phishing attack and urging customers not to click on suspicious links. Trezor’s security team has disabled the domain used in the attack and is currently investigating how the hackers may have gained access to the company’s legitimate address.
Our third-party email provider has been breached. Please be aware that the email titled “Critical Security Alert: STM32 Entropy Vulnerability” is not from us and is a phishing attempt. Do not click any links. We have taken down the domain and are investigating the incident, including how the attackers gained access to our legitimate domain.
— Trezor (@Trezor) September 9, 2026Nick Neuman, co-founder and CEO of Casa, suggested that the phishing campaign may not be limited to Trezor—users of BitBox hardware wallets have also received similar emails. The businessman believes hackers may have compromised the email newsletter service used by both Trezor and BitBox.
There are currently convincing phishing emails being sent out from hardware wallet companies (Trezor and BitBox have been reported at least). It’s likely that a marketing email provider was compromised, which means more customer emails may have been leaked. Stay alert and do not trust emails from providers that ask you to take action via suspicious-looking links. (The email in this image is the phishing email, so there is no confusion about actual vulnerabilities.)
— Nick Neuman (@Nneuman) September 9, 2026A wave of phishing attacks followed the disclosure of a vulnerability in Coldcard hardware wallets. Over the summer, hackers stole more than $130 million in Bitcoin from users of this wallet by exploiting a 2021 firmware flaw. The vulnerability drastically reduced entropy during seed phrase generation—from 128 bits to 40 bits.
Last year, Trezor wallet users received phishing emails about quantum attacks—scammers offered to download a patch to enhance wallet protection against future vulnerabilities.

