๐Ÿ“… Friday, 11 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Hacker Jebol Email Trezor dan Kirim Peringatan Palsu STM32 - Lolos Verifikasi Resmi

Hackers Breach Trezor Email Provider to Send Fake STM32 Alert - Passing Official Verification

Hackers breached a third-party email provider for Trezor and sent phishing messages disguised as a “Critical Security Alert: STM32 Entropy Vulnerability.” The fake email claimed there was a hardware-level vulnerability in the STM32 microcontroller used in Trezor hardware devices, potentially causing users’ recovery phrases to have insufficient entropy. The phishing emails were sent using Sendinblue infrastructure and successfully passed standard DKIM, SPF, and DMARC security verifications - evidence that Trezor’s legitimate domain was compromised by attackers.

The phishing emails appeared in targeted inboxes hours before Trezor had the chance to issue an official warning. That time lag meant many users received the messages without prior warning. The Trezor team swiftly took down the domain used by the attackers and stated that the emergency security alert did not come from them.

More Than One Target

Casa CEO Nick Neuman noted that this scam campaign likely extends beyond Trezor, observing that BitBox device users also reportedly received similar emails. Casa CSO Jameson Lopp warned that threat actors may have breached an email provider servicing channels for both Trezor and BitBox. The malicious emails spread a uniform threat claiming both victim devices suffered from a flawed RNG requiring an urgent security update.

The phishing messages capitalized on lingering public anxiety over the recent Coldcard exploit. That previous vulnerability incident cost users over $130 million in Bitcoin, and the momentum from that panic is now being used to pressure new victims into acting hastily.

Logistics Vendor Weak Points

The phishing case follows another data security issue involving Trezor’s third-party service providers. In August 2026, Trezor reported a data breach from shipping provider ShipMonk. That logistics security flaw exposed the personal information of 80,689 customers, including full names, email addresses, phone numbers, and physical shipping addresses.

For crypto asset holders, business partner data breaches present a clear irony. The high-level security embedded directly into hardware wallets loses almost all meaning when hackers can breach a distributor’s email channels to trick customers into handing over access directly.

Reported via Decrypt.

Read also: Cronos Reverses $111 Million in Transactions - But Hacker Escaped with $9.19 Million Before Network Shutdown


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share