1

Heads Up: Fake “STM32 Entropy” Alerts Targeting Trezor and BitBox Users

What happened

Short version: some sneaky phishing emails pretending to be from Trezor and BitBox popped up with a scary subject about an “STM32 entropy vulnerability.” Recipients were told to click links and follow urgent instructions — don’t. Both wallet makers warned users that the messages weren’t legitimate and that a third-party email/newsletter provider appears to have been compromised.

Trezor said the bogus message didn’t come from them, that they pulled down the malicious domain, and that their devices themselves remain safe. BitBox reported a similar impersonation, warning subscribers not to follow any email instructions and saying it’s likely their newsletter provider was breached. By the time both companies updated users, many of the phishing links had already been removed, but investigations were still ongoing.

How to stay safe (aka do the opposite of clicking shady links)

If you see an urgent-sounding security email from a wallet provider: breathe, don’t panic, and definitely don’t click. The golden rule here is: never share your recovery seed or type it into a website or form. Anyone who gets your backup words can empty your wallet — that’s not paranoia, that’s reality.

Other quick, practical moves: ignore attachments and embedded links in the suspicious email, and verify any announcement by checking the wallet maker’s official site or verified social accounts (type the URL yourself; don’t follow the email link). If you subscribed to newsletters, contact the company through their official contact page to confirm if they actually sent anything, and report the phishing message to them so they can block it.

Also consider tightening up email security: enable two-factor authentication, use a separate email for important financial accounts if you can, and be cautious about which newsletters you allow to send you messages. If you ever feel unsure, treat the message like a stranger offering you free pizza in a dark alley — suspicious and probably a trap.

Bottom line: wallets are safe when handled correctly, but your recovery seed is sacred. Keep it private, treat unexpected security emails like hot potatoes, and always verify via official channels before doing anything.