A fake “STM32 Entropy Vulnerability” alert reportedly came through infrastructure associated with Trezor’s real email provider. Days earlier, the company confirmed that nearly 81,000 customers were affected by a separate shipping-data breach.
Normally, spotting a crypto phishing email starts with one piece of advice:
Check the sender.
Wrong domain?
Delete it.
Strange spelling?
Delete it.
Suspicious link?
Delete it.
That rule became a lot less comfortable yesterday.
On September 9, Trezor users began reporting emails with the subject:
“Critical Security Alert: STM32 Entropy Vulnerability”
The message claimed there was a serious entropy problem affecting Trezor hardware wallets.
The warning was fake.
But the email looked unusually convincing.
Why?
Because Trezor later confirmed that a third-party email provider it uses had been breached.
The company warned users not to click links in the message and said it was investigating how attackers gained access to infrastructure connected to its legitimate domain.
That changes the phishing equation.
This Wasn’t Just Someone Spoofing “Trezorr-Support.com”
Users on Trezor’s own forum inspected the email headers and reported that messages appeared to come through:
mailing.trezor.io
One user described receiving several scam emails through what appeared to be Trezor’s real mailing infrastructure.
Another inspected the malicious “offline” verification page offered by the phishing campaign and reported that the embedded code attempted to send entered recovery information to a Telegram bot.
That is what makes this incident different.
The victim does not necessarily see:
random-scam-wallet.xyz
They may see something that appears to be connected to a brand they actually trust.
And suddenly:
“Check the sender.”
is no longer enough.
The Fake Vulnerability Was Cleverly Chosen
The phishing campaign used the phrase:
STM32 Entropy Vulnerability
That sounds highly technical.
More importantly, it sounds believable.
Most hardware-wallet owners know that seed generation depends on secure randomness.
So a warning claiming:
“Your device may have generated a weak recovery phrase.”
creates the perfect emotional reaction.
Fear.
And fear creates urgency.
The natural next question becomes:
“How do I check whether my seed is affected?”
That is exactly where the attacker wants you.
Because any “security checker” that eventually asks for your recovery phrase has crossed the line.
Your 12 or 24 recovery words are not diagnostic information.
They are wallet-control information.
And This Happened Right After Another Trezor Security Story
The timing makes this even more interesting.
In August, Trezor disclosed that logistics provider ShipMonk had suffered a data breach involving customer order information.
Initially, roughly 14,000 customers were believed to be affected.
Then the story got worse.
On September 2, Trezor learned that older data that should have been deleted was still present in ShipMonk’s systems.
Another approximately 67,000 U.S. customers were affected.
Trezor now lists the total number of impacted customers as 80,689. Exposed information included combinations of names, email addresses, telephone numbers, shipping addresses and order information.
To be clear:
the ShipMonk incident and yesterday’s email-provider breach are separate incidents.
But together they reveal something important.
Hardware-Wallet Security Is Bigger Than the Hardware Wallet
Imagine your Trezor device itself is working perfectly.
Private keys remain offline.
Nobody extracted the seed from the device.
The firmware is fine.
But elsewhere, an attacker may have access to information such as:
your name,
your email,
your telephone number,
your shipping address,
and the fact that you purchased a hardware wallet.
Then another compromised system gives attackers the ability to send an email that looks unusually authentic.
This creates an entirely different type of attack surface.
The attacker does not need to defeat the cryptography.
They need to defeat your trust.
A Real Sender Does Not Make a Real Request
This may be the most useful lesson from the entire event.
For years we have been taught:
Check the sender address.
Good advice.
But it needs an update.
A better rule is:
Never judge a crypto-security request only by who appears to have sent it. Judge what the message is asking you to do.
If an email asks you to:
- enter your recovery phrase,
- download an “offline seed checker,”
- migrate funds urgently,
- restore your wallet through an unfamiliar tool,
- install unexpected software,
- or reveal private recovery information,
the sender address should not override your security rules.
Even if the email looks real.
Even if the domain looks real.
Even if the warning refers to a real technical concept.
The Hardware Wallet Cannot Protect You From This Step
This is where I think hardware-wallet marketing is often misunderstood.
A Trezor, Ledger or another hardware signer can help isolate private keys from an everyday computer.
That is valuable.
But the device cannot stop someone from manually typing the recovery phrase into a malicious page.
Once the recovery phrase is exposed, the attacker may no longer need the original hardware wallet.
That is why I think of self-custody as several separate layers:
Hardware wallet
Protects the signing environment.
Recovery backup
Preserves the ability to restore the wallet.
Physical security
Protects that backup from loss or unauthorized access.
Operational security
Protects the user from phishing, impersonation and malicious workflows.
One layer does not replace the others.
This Is Also Why “Offline Backup” Should Actually Mean Offline
At CryptoSafeKit, we spend a lot of time discussing recovery storage because users often buy a hardware wallet and then treat the recovery phrase much less carefully than the device itself.
Some photograph it.
Some type it into Notes.
Some email it to themselves.
Some store it in cloud drives.
And some will enter it into a website if the website claims their hardware wallet is in danger.
A physical recovery backup—whether paper or something more durable such as a metal backup—solves a very specific problem:
keeping recovery information physically available without requiring an online copy.
For example, our VAULTIGO 4-Letter Metal Seed Phrase Backup stores standard English BIP39 recovery information offline using the first four letters of each word and reusable stainless-steel tiles. It is specifically a physical backup system; it does not connect to the internet or verify wallets online.
But even a metal backup cannot stop phishing if the owner later types those words into a malicious website.
That part is still human security.
The Most Dangerous Phrase in Crypto May Be “Urgent Security Update”
Think about how many attacks begin with urgency.
Your wallet is vulnerable.
Your seed may be weak.
Your account is compromised.
Your assets must be migrated.
Verification required immediately.
The objective is not merely to scare you.
It is to shorten the amount of time you spend thinking.
Because if you stop and ask:
“Why would Trezor need my recovery phrase to fix an email-security incident?”
the attack becomes much easier to recognize.
The Rule I Would Use After Yesterday
If I receive an unexpected security email from a hardware-wallet company, I would not act from the email.
I would:
close it,
open the manufacturer’s official website independently,
check its security notices,
verify the issue through another trusted channel,
and only then decide whether any action is actually required.
I would never begin a recovery process because an unsolicited email told me to.
And I would never enter recovery words into a website simply because the page looked official.
Nearly 81,000 Customers Changes the Threat Model
The ShipMonk breach did not expose Trezor private keys.
Yesterday’s email incident did not mean Trezor hardware wallets suddenly stopped working securely.
But these events matter because attackers do not always need the private key first.
Personal information can help identify potential targets.
Trusted communication infrastructure can help make a message believable.
Fear can push the victim toward the final step.
And only at that final step does the attacker need the secret.
That is modern crypto phishing.
It is increasingly less about obvious fake websites.
And more about building a convincing chain of trust.
One Question for the Comments
This is what I genuinely want to know:
If a crypto security email passed every visual test—correct company, correct branding, apparently correct sender domain—what would make you stop before following its instructions?
Would you independently check the company website?
Ignore all unsolicited recovery warnings?
Call support?
Or would a legitimate-looking sender still make you trust the message?
Yesterday’s Trezor incident makes that question much harder than it used to be.
Please do not share real recovery words, wallet addresses, balances, email addresses or physical backup locations in the comments.
Security disclaimer: The September 9 phishing campaign was not evidence that Trezor hardware-wallet private keys had been compromised. Trezor stated that its third-party email provider was breached and identified the “Critical Security Alert: STM32 Entropy Vulnerability” email as phishing. The earlier ShipMonk customer-data breach was a separate incident. Never provide a recovery phrase, private key, PIN or passphrase in response to an unsolicited email, website, document, telephone call or support message.