Back Cryptopotato Fake Trezor Warning Claims 25% of Devices Are Vulnerable in Latest Phishing Campaign
Hardware wallet maker Trezor said its third-party provider was breached and warned users that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” was not sent by the company but was instead a phishing attempt.
The company urged users not to click any links.
In an update on X, Trezor said it had taken down the domain and was investigating how hackers accessed its legitimate domain. The phishing message in question attempted to convince users that a serious security flaw has been found in STM32 microcontrollers used in its devices. According to the fabricated warning, STM32 microcontrollers could generate recovery phrases without enough randomness, potentially putting users’ funds at risk. The email further claims that as many as 25% of devices may be affected.
The issue may not be limited to Trezor users, according to Casa CEO and co-founder Nick Neuman. He noted that reports of similar messages have surfaced among people using the BitBox device as well.
This isn’t the first time a third-party partner connected to Trezor has suffered a security breach. In August, the platform disclosed a similar security incident involving its logistics partner, ShipMonk, which compromised personal details tied to a large number of customers.
The exposed information included and delivery data. An earlier disclosure put the number of affected individuals at 13,689. However, Trezor later confirmed that roughly 67,000 additional US customers were impacted, which pushed the total to 80,689 people whose information was exposed.
A separate security test also raised concerns the TROPIC01 chip found in Trezor’s Safe 7 wallet. In June, Ledger’s Donjon researchers found that, with specialized equipment and physical access to a device, an attacker could interfere with the chip while it checks firmware.
CZ Says Software Wallets Avoid Risks Seen in Trezor Leak
Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardware Wallet Customers
Fake Uniswap Website Drains Crypto Wallets as Scammers Pocket $400K
The researchers used a carefully focused 1064 nm laser to trigger faults during the boot and update process. This could allow modified firmware to run. Trezor, however, said the finding does not put users’ funds at risk.
Blockchain investigator ZachXBT has been pretty blunt hardware wallets in the past. He had earlier said that all hardware wallets are “complete garbage” and that he wouldn’t use them for important transactions or to store funds, and suggested keeping a separate iPhone just for wallet use instead.
Chayanika has been working as a financial journalist for seven years. A graduate in Political Science and Journalism, her interest lies in regulatory implications with a focus on technological evolution in the crypto realm.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
