Trezor users targeted by phishing emails claiming an STM32 vulnerability

iconBitMedia
Share
AI summary iconSummary
Trezor users received phishing emails citing a vulnerability alert regarding an STM32 entropy flaw. The emails falsely claimed a security breach could expose seed phrases. Trezor denied any involvement and took down the malicious domain. Experts suspect a third-party email provider may have been compromised. The campaign follows a recent Coldcard exploit that resulted in a major Bitcoin theft.

Unknown actors sent emails to wallet owners with the subject "Critical Security Alert: STM32 Entropy Vulnerability," masquerading as an urgent security warning. The email claimed that Trezor engineers had discovered a serious vulnerability in the STM32 microcontrollers used in the company’s devices. According to the message, this flaw affects every fourth device and could lead to entropy issues—where numerous predictable patterns arise during seed phrase generation, allowing an attacker to more easily guess the secret phrase.

Trezor stated that it did not send these emails, calling the campaign a targeted phishing attack and urging customers not to click on suspicious links. Trezor’s security team has disabled the domain used in the attack and is currently investigating how the hackers may have gained access to the company’s legitimate address.

Nick Neuman, co-founder and CEO of Casa, suggested that the phishing campaign may not be limited to Trezor—users of BitBox hardware wallets have also received similar emails. The businessman believes hackers may have compromised the email newsletter service used by both Trezor and BitBox.

A wave of phishing attacks followed the disclosure of a vulnerability in Coldcard hardware wallets. Over the summer, hackers stole more than $130 million in Bitcoin from users of this wallet by exploiting a 2021 firmware flaw. The vulnerability drastically reduced entropy during seed phrase generation—from 128 bits to 40 bits.

Last year, Trezor wallet users received phishing emails about quantum attacks—scammers offered to download a patch to enhance wallet protection against future vulnerabilities.


Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.