Trezor’s email provider has been breached. Phishing attempt - don’t click.
Response from Trezor:
Hello,
Thank you for reaching out to the Trezor Support team.
The email that you received is not legitimate - it is a phishing scam; please do not click or interact with it.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
Best regards,
Dominik
Trezor Support
Trezor | SatoshiLabs
Phishing email received:
---------- Forwarded message ---------
From: Trezor Security help@trezor.io
Subject: Critical Security Alert: STM32 Entropy Vulnerability
Critical Security Alert:
STM32 Entropy Bug Identified
Urgent update regarding hardware microcontroller vulnerability
Dear customer,
We have some difficult news to share. Unfortunately, our engineering team has identified a critical hardware-level vulnerability in the STM32 microcontrollers used in a range of Trezor devices.
Currently we believe the majority of defective devices were initialized prior to 2023, however some newer devices also may be vulnerable. The bug is a hardware factory defect present in an estimated 1 in 4 devices.
The vulnerability results in:
Insufficient randomness in recovery phrase generation
Exposure of seeds to brute-force cracking
Seeds with as little as 40 bits of entropy
The incident affects a portion of our user base with full exposure (critically low 40-bit entropy) and others with partial exposure. The scope is limited due to Trezor’s strict security and initialization monitoring policies.
All potentially affected customers are being contacted separately by email.
Our software systems remain secure, but affected devices could be vulnerable to mathematical brute-force attacks until a new seed is generated.
NEVER enter your recovery phrase on a website or share it with anyone, and only check for updates on official Trezor channels.
We are deeply sorry to the community and those affected.
Check to see if you're affected
Click the link above to open the entropy check tool in your browser. If your email client blocks the link, use View in browser below and try again.
What the check reveals
✓ Verification of STM32 hardware RNG bug and 40-bit entropy (crackable seeds)
✓ BIP-39 checksum failures (12, 18, or 24 words) and SLIP-39 share validation (20 or 33 words)
✓ Pass/fail entropy score so you know if immediate action is required
✓ Extended public key export for online wallet verification
Do not ignore this check. Wallets with weak entropy remain vulnerable to brute-force attacks until a new seed is generated on your device.
We know that trust is earned, and we are devastated to have put yours at risk. Our entire engineering team is working around the clock to provide support and ensure a smooth migration for anyone affected. We are truly sorry for the stress and concern this causes.
With our deepest apologies,
The Trezor Team
trezor.io | Support | Trezor Suite
Complete xPub verification
© SatoshiLabs s.r.o. All rights reserved.
Trezor company s.r.o., Kundratka 2359/17a, 180 00 Praha 8, Czech Republic
You received this e-mail because you subscribed to Trezor security notifications or use Trezor Suite.
[Unsubscribe](file:///private/var/mobile/Containers/Data/Application/CC49C513-7BA3-44CE-9CDC-51FC36328EE9/tmp/WWW/#m201424860617392472) | [Update preferences](file:///private/var/mobile/Containers/Data/Application/CC49C513-7BA3-44CE-9CDC-51FC36328EE9/tmp/WWW/#m201424860617392472) | [View in browser](file:///private/var/mobile/Containers/Data/Application/CC49C513-7BA3-44CE-9CDC-51FC36328EE9/tmp/WWW/#m201424860617392472)
If you wish to unsubscribe f
[link] [comments]