If a message titled "Critical Security Alert: STM32 Entropy Vulnerability" landed in your inbox this week, apparently from Trezor, telling you that one in four devices shipped with a defective chip and inviting you to run an entropy check in your browser, stop. Do not click anything in it. Trezor did not send it.
Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
If a message titled "Critical Security Alert: STM32 Entropy Vulnerability" landed in your inbox this week, apparently from Trezor, telling you that one in four devices shipped with a defective chip and inviting you to run an entropy…
CryptoTicker
Publisher
Sep 10, 2026 at 8:13 AM UTC · 4 分で読める

The company confirmed on Wednesday that attackers had gotten into its email infrastructure and used it to blast a fake security warning to customers. The email is a seed harvester dressed up as an apology, and it is one of the more convincing phishing attempts the hardware wallet space has seen in years.

What Does the Fake Trezor Security Alert Actually Claim?
The email opens with the tone of a company confessing to a disaster. It claims Trezor's engineering team found a hardware-level defect in the STM32 microcontrollers inside its devices, that the flaw was baked in at the factory, and that roughly one device in four is affected. It says the bug produces recovery phrases with as little as 40 bits of entropy, leaving seeds open to brute-force cracking.
It then does something clever. It tells the reader never to enter a recovery phrase on a website or share it with anyone. Two paragraphs later, it invites that same reader to click a link and run an "entropy check tool" that verifies BIP-39 checksums across 12, 18 and 24-word phrases, validates SLIP-39 shares, and exports extended public keys.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
