Trezor users received a sophisticated phishing email on September 9 that posed as a critical hardware-security warning. The message claimed a flaw in STM32 entropy could leave wallet seeds dangerously weak, then directed recipients to a browser-based “entropy check.”
That check was the trap. A subsequent legitimate Trezor warning said an unauthorized email had been sent through a third-party email service provider while impersonating the company. Users were told not to follow suspicious links or provide personal information.
Bitcoin itself was not hacked. The incident targeted the systems and people around Bitcoin: email infrastructure, user trust and the custody of recovery words.
What the fake Trezor security alert claimed
The phishing message used a technical-sounding subject: “Critical Security Alert: STM32 Entropy Bug Identified.” It alleged that a hardware vulnerability could reduce wallet-seed security to as little as 40 bits and claimed roughly one in four devices might be affected.
It then offered a browser tool that supposedly could check a wallet's entropy. That request should be treated as hostile. A recovery seed entered into a website is no longer an offline secret; anyone who receives it can recreate the wallet and authorize transactions.
The language was effective because it borrowed details from a real class of wallet risk. Coinkite recently disclosed an entropy problem affecting certain COLDCARD firmware releases. But a real incident involving one manufacturer's build process does not validate an unsolicited claim about another device.
What Trezor actually tells users
Trezor's official scams and phishing guidance says requests for a wallet backup, PIN, password or verification code are scams. Trezor says it will never ask for a wallet backup and that legitimate firmware and Trezor Suite updates should be completed through authentic device and desktop-app workflows.
A polished logo, correct grammar or technical vocabulary does not establish authenticity. Trezor specifically warns that professional-looking messages can still be fraudulent and that users should verify information through official channels.
Trezor also disclosed in August that customer and order data held by shipping provider ShipMonk had been exposed. Its September 4 update said names, email addresses, telephone numbers, shipping addresses and order numbers were involved for affected customers. Trezor said its products and systems remained secure but warned the leaked information could make phishing more convincing.
Trezor has not publicly established that the ShipMonk incident caused this specific email campaign. The responsible conclusion is narrower: exposed identity and order data can increase social-engineering risk, and the September 9 message used that familiar pressure point.
Was Bitcoin hacked?
No. Bitcoin's base protocol, consensus rules and blockchain continued operating normally.
A seed phrase is a wallet credential. A hardware wallet protects that credential and signs transactions, but neither the device nor the Bitcoin network can stop a person from voluntarily typing recovery words into an attacker-controlled form.
The distinction matters:
- Bitcoin protocol: the distributed rules nodes use to validate blocks and transactions.
- Hardware wallet: a device intended to isolate private keys and approve transactions.
- Recovery seed: the backup that can recreate the wallet and control its funds.
- Phishing: social engineering designed to make the user reveal that backup or authorize a harmful action.
This incident belongs in the fourth category. Receiving the email did not alter a wallet, weaken a seed or move bitcoin by itself.
Is my Trezor at risk?
If you only received the email and did not enter a wallet backup, PIN or passphrase into its site, the message alone did not compromise your funds. Delete it, avoid its links and verify any claimed update in the official Trezor Suite application or on trezor.io.
If you entered a wallet backup into the linked form, treat that seed as compromised. Using a clean, trusted device and official software, create a new wallet with a new seed, verify a receiving address on the hardware-wallet screen, make a small test transfer and then move the remaining funds. Do not reuse the exposed backup.
If you are unsure what each credential does, Bitcoin Almanack's seed phrase vs. passphrase guide separates recovery words, passphrases and PINs before you take action.
What should Trezor users do now?
- Do not click the email's checker or download an attachment.
- Never type recovery words into a browser, email, chat or support form.
- Open Trezor Suite from a known installation rather than an email link.
- Confirm warnings through Trezor's official site and support channels.
- If recovery words were exposed, migrate to a securely generated new seed.
- Review the Bitcoin self-custody guide before moving a material balance.
Why hardware-wallet users attract phishing
Self-custody removes a financial intermediary, but it also makes the recovery backup a high-value target. Bitcoin transactions are final by design, and an attacker with valid keys does not need a bank to approve a transfer or reverse it later.
That shifts many practical attacks away from Bitcoin's cryptography and toward the human layer. Purchase records can identify likely wallet owners. Urgent warnings can create fear. A fake verification page can turn that fear into a usable private key.
The safest response is procedural: distrust unsolicited urgency, verify on the hardware-wallet display, keep backups offline and separate, and use only official update channels.
Does this change the Trezor Safe 5 ranking?
No device-level evidence in this incident justifies changing Bitcoin Almanack's current Trezor Safe 5 assessment. The Safe 5 remains our top cold-wallet pick for most people, and readers can compare its security model directly in Trezor vs. Ledger or review the full Bitcoin wallet rankings.
That does not make the phishing campaign unimportant. It means the remedy must match the failure: strengthen verification and recovery-seed custody rather than suggesting that Bitcoin or the Safe 5's cryptography was breached without evidence.
Quick answers
Was the Trezor phishing email real?
The security claims and browser checker were fraudulent. Trezor warned users about an unauthorized message sent through a third-party email service provider.
Did the email hack my wallet?
Receiving an email does not expose a wallet. Risk becomes acute if recovery words, a passphrase or other credentials were entered into the linked site.
Should I enter my seed to test its entropy?
No. Never enter a wallet backup into a website. A legitimate wallet manufacturer or support agent does not need your recovery words.
