# Trezor Users Warned: Fake Security Emails Trezor said a third-party email provider was compromised and attackers used its infrastructure to send fake security alerts. Emails titled **“Critical Security Alert: STM32 Entropy Vulnerability”** were not from Trezor and were phishing attempts. The company disabled the domain and is investigating. ## What Did the Fake Email Claim? The message falsely claimed a **critical hardware vulnerability** in STM32 microcontrollers could weaken recovery-phrase generation and put assets at risk. The goal was apparently to create urgency and direct users to malicious links. Trezor urged users not to click them. ## The Real Risk Is Phishing The incident does not mean Trezor devices were compromised. The attack centered on **third-party email infrastructure**, making phishing and social engineering the main threat. Attackers seek recovery phrases. A compromised phrase can give them control of wallet assets without physical access. ## BitBox Users Also Targeted Casa CEO Nick Neuman said BitBox users received similar messages. Jameson Lopp noted that email providers used by Trezor and BitBox may have been targeted. This could indicate a broader campaign targeting **email and marketing infrastructure used by crypto companies**. ## Trezor Had Also Reported a Data Breach In August, Trezor said a ShipMonk breach exposed data belonging to **80,689 customers**, including names, emails, phone numbers and shipping addresses. Such data can help attackers create phishing attempts. ## The Critical Rule **A recovery phrase should never be entered into a website, email form, or given to another person under any circumstances.** Even official-looking messages may be fraudulent. Requests to re-enter, verify or recover a wallet through a link are major warning signs. ## A New Front in Crypto Security Crypto security risks extend beyond blockchain and hardware. Email services and other third parties are also attack surfaces. $BTC $ETH
