Hardware-wallet makers Trezor and BitBox warned users on Sept. 9 about phishing emails impersonating their brands, urging recipients to avoid the messages' links and instructions.
Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders
Hardware-wallet makers Trezor and BitBox warned users on Sept. 9 about phishing emails impersonating their brands, urging recipients to avoid the messages' links and instructions.
cryptoslate.com
Publisher
Sep 11, 2026 at 8:10 AM UTC · Updated hace un día · 2 min de lectura

Trezor said its third-party email provider had been breached and reiterated on Sept. 10 that its wallets remained safe.
Trezor identified an email titled “Critical Security Alert: STM32 Entropy Vulnerability” as a phishing attempt. The company said the message did not come from Trezor and told recipients not to click any link. The technical-sounding subject was part of the fake security alert, rather than a vulnerability announcement from the wallet maker.
In its Sept. 9 warning, Trezor said it had taken down the domain and was investigating how attackers accessed its legitimate domain. The following day, Trezor said its wallets were still safe and again described the incident as a breach at a third-party email provider.
Most phishing links appeared to have been taken down by the time of that update, according to BitBox, which said its investigation was continuing.
Keep recovery seeds private
The warnings concern emails impersonating wallet companies. Trezor's reassurance about its wallets does not make following a phishing message safe: its standing security guidance says anyone who obtains a wallet backup, also called a recovery seed, can move the funds.
Market Context
Bitcoin
BTC
$77,343
-0.71% (24H)
Market Cap
$1.55T
24H Volume
$15.8B
24H High
$77,965
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
