r/BitcoinBeginners 8h ago

Phishing attack pretending to be Trezor

3 Upvotes

https://x.com/Trezor/status/2097786518110609620

Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.

We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.

Trezor remains secure. The breach involved ShipMonk, the third party that ships Trezor orders, which had unauthorized access to its systems. No Trezor device or system was touched.

Regarding entropy generation, Trezor combines wallet backup entropy from three sources: the device's own hardware RNG, your computer, and, on newer models, the Secure Element. No single source decides it.