AdvertisementAdvertisementAdvertisementAdvertisement
Technology

STM32 Phishing: How Attackers Compromised Trezor's Provider

9/10/2026, 11:36 AM • Evgenia Sliv

(edited: 09/10/2026)

STM32 Phishing: How Attackers Compromised Trezor's Provider

Trezor confirmed that its third-party email distribution provider was compromised, and attackers sent phishing emails to users. This is already the third service failure involving a Trezor vendor in four weeks.

The emails were titled "Critical Security Alert: STM32 Entropy Vulnerability". They passed SPF, DKIM, and DMARC checks, making them particularly convincing: they were sent from infrastructure authorized to send emails on behalf of Trezor, and appeared in Gmail as signed by the company. Trezor stated that it has disabled the domain behind the campaign and is investigating how attackers gained access to infrastructure associated with the company's legitimate domain. Wallets, keys, and backup copies were not compromised.

The fraudulent email claimed that there was a critical entropy vulnerability in the STM32 microcontrollers used in Trezor devices — insufficient randomness during recovery phrase generation — which could put users' funds at risk. The email also stated that the vulnerability could affect up to 25% of devices.

The phishing campaign became the third incident in a chain of Trezor partner failures. In August, ShipMonk — the partner responsible for fulfilling Trezor orders — was hacked. By September 4, that breach had exposed the data of more than 80 000 users, including names, phone numbers, and home addresses. Earlier, in 2024, 66 000 users were warned following a hack of the Trezor support portal.

Users who received the phishing emails were confronted with a fake security verification process. According to one user on the Trezor forum, a standalone HTML file attached to the email was capable of transmitting entered data to Telegram. Parallel incidents affected users of BitBox (a Swiss hardware wallet manufacturer) and CoinTracking (a cryptocurrency portfolio management service). Some community researchers suggested that the common point could be the email marketing provider Brevo, though Trezor itself did not name that vendor.

Popular news