Fake Trezor Warning Claims 25% of Devices Are Vulnerable in Latest Phishing Campaign
Trezor users are being targeted again with sophisticated phishing messages.
cryptopotato.com
Publisher
Sep 10, 2026 at 6:10 AM UTC · Updated 5 saat önce · 2 dk okuma

Trezor users are being targeted again with sophisticated phishing messages.
Hardware wallet maker Trezor said its third-party provider was breached and warned users that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” was not sent by the company but was instead a phishing attempt.
The company urged users not to click any links.
Trezor Phishing Scam
In an update on X, Trezor said it had taken down the domain and was investigating how hackers accessed its legitimate domain. The phishing message in question attempted to convince users that a serious security flaw has been found in STM32 microcontrollers used in its devices. According to the fabricated warning, STM32 microcontrollers could generate recovery phrases without enough randomness, potentially putting users’ funds at risk. The email further claims that as many as 25% of devices may be affected.
The issue may not be limited to Trezor users, according to Casa CEO and co-founder Nick Neuman. He noted that reports of similar messages have surfaced among people using the BitBox device as well.
This isn’t the first time a third-party partner connected to Trezor has suffered a security breach. In August, the platform disclosed a similar security incident involving its logistics partner, ShipMonk, which compromised personal details tied to a large number of customers.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
