Back Finance.Biggo Trezor Warns Users of Phishing Emails After Third
Hardware wallet maker Trezor is urging customers to exercise caution after a security incident at one of its third-party email service providers allowed attackers to distribute fraudulent messages designed to look like official company communications.
The company disclosed the breach on September 9 via its official account on X, the platform formerly known as Twitter. Trezor said an external email provider it relies on had been compromised, and that messages bearing the subject line "Critical Security Alert: STM32 Entropy Vulnerability" were not sent by the company. The emails are phishing attempts, Trezor said, and users should not click any links contained within them.
The domain used in the phishing campaign has already been blocked, according to the company's statement. Trezor added that it is investigating the specific circumstances of the incident, including how the attackers were able to gain access to its legitimate domain. The company did not disclose whether user assets or the hardware wallets themselves were affected, nor did it provide details on the scope of the breach or the number of recipients targeted.
What the Breach Means for Users
The incident highlights a persistent risk in the cryptocurrency ecosystem: attackers exploiting peripheral infrastructure rather than the core product itself. In this case, the compromised system was not Trezor's wallet hardware or its signing software, but an email provider that handles outbound messaging on the company's behalf. That distinction matters, because it means the attackers gained the ability to impersonate the brand through official-looking communications, rather than directly accessing user funds or private keys.
The phishing email's framing was deliberate. By labeling the message as a "Critical Security Alert" referencing an "STM32 Entropy Vulnerability," the attackers borrowed the tone and urgency users would expect from a legitimate wallet vendor. STM32 is a family of microcontrollers widely used in hardware devices, and the mention of an entropy vulnerability would plausibly alarm security-conscious cryptocurrency holders, prompting them to act quickly rather than scrutinize the message.
Trezor has not released samples of the phishing emails, the sender addresses used, or the specific actions the messages requested. The company also has not confirmed whether any users fell victim to the scheme.
A Pattern of Messaging-Related Incidents
This is not the first time Trezor has dealt with security concerns tied to its messaging infrastructure. The company has previously warned users after a data breach involving its email systems, an incident that placed thousands of customers on phishing alert. The broader hardware wallet industry has faced similar challenges, with competitor SafePal also experiencing a data breach that exposed cryptocurrency owners to risk.
Consumer protection authorities have long warned the tactics used in these campaigns. Attackers commonly impersonate a trusted company and claim there is a problem with an account or a payment, according to guidance from the U.S. Federal Trade Commission. The goal is to manufacture urgency and push recipients toward taking an action they would otherwise avoid, such as entering credentials on a fake website or approving a malicious transaction.
How Users Should Respond
Trezor's guidance for users centers on verification. Anyone who receives an unexpected email claiming to be from the company should independently navigate to Trezor's official channels by typing the web address directly into their browser or using a saved bookmark, rather than following links embedded in the message.
Security experts emphasize that legitimate hardware wallet companies never request recovery phrases or private keys through email under any circumstances. Users should never enter a wallet recovery seed into a page reached from an unsolicited message, and should avoid clicking links or opening attachments in suspicious communications.
Receiving a phishing email does not by itself indicate that funds are compromised, and users should not move assets based solely on an alert contained in such a message. The pattern of fraudulent approvals seen in other cryptocurrency scams, including fake anti-money-laundering checkers that trick users into wallet-draining approvals, underscores why unsolicited prompts to act deserve independent verification before any response.
For Bitcoin holders, the episode serves as a reminder that self-custody security rests on two foundations: the integrity of the signing device and the secrecy of the seed phrase. Both remain under the user's control even when a vendor's peripheral systems, such as an email provider, are breached. The Bitcoin network's own settlement assurances, anchored in proof-of-work and validated independently by every full node, are unaffected by compromises at a company's email vendor.
Trezor has not provided a timeline for its investigation or indicated whether additional details the breach will be released. The company's initial disclosure focused on warning users the phishing risk rather than detailing the technical specifics of how the email provider was compromised.
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
