{"id":13094,"date":"2026-09-11T08:57:24","date_gmt":"2026-09-11T08:57:24","guid":{"rendered":"https:\/\/cryptonews.uk.com\/?p=13094"},"modified":"2026-09-11T08:57:24","modified_gmt":"2026-09-11T08:57:24","slug":"attackers-exploit-fake-stm32-vulnerability-alert-to-target-trezor-and-bitbox-holders","status":"publish","type":"post","link":"https:\/\/cryptonews.uk.com\/?p=13094","title":{"rendered":"Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/09\/trezor-bitbox-phishing-alert.jpg\" \/><\/p>\n<div data-cs-editorial-quote-scope=\"\" data-cs-image-viewer-scope=\"\" data-single-article-content=\"\">\n<p>Hardware-wallet makers Trezor and BitBox warned users on Sept. 9 about phishing emails impersonating their brands, urging recipients to avoid the messages&#8217; links and instructions.<\/p>\n<p>Trezor said its third-party email provider had been breached and reiterated on Sept. 10 that its wallets remained safe.<\/p>\n<p>Trezor identified an email titled \u201cCritical Security Alert: STM32 Entropy Vulnerability\u201d as a phishing attempt. The company said the message did not come from Trezor and told recipients not to click any link. The technical-sounding subject was part of the fake security alert, rather than a vulnerability announcement from the wallet maker.<\/p>\n<p>In its Sept. 9 warning, Trezor said it had taken down the domain and was investigating how attackers accessed its legitimate domain. The following day, Trezor said its wallets were still safe and again described the incident as a breach at a third-party email provider.<\/p>\n<p>BitBox issued its own impersonation warning on Sept. 9, telling users not to follow the phishing email&#8217;s instructions while it investigated. In a subsequent update that day, BitBox said its preliminary review found it very likely that its newsletter provider had been compromised.<\/p>\n<p>BitBox also said other Bitcoin companies had been targeted and appeared to share the same newsletter provider. BitBox said it had warned all newsletter subscribers, contacted the provider and reported the phishing domains.<\/p>\n<aside id=\"cs-inline-newsletter-1\" class=\"cs-inline-newsletter\" data-inline-newsletter=\"\" data-newsletter-placement=\"article-midpoint\" data-newsletter-pending-label=\"Joining\u2026\" data-newsletter-pending-status=\"Joining the Daily Brief\u2026\" data-newsletter-email-required-message=\"Before sending, please provide your email address.\" aria-labelledby=\"cs-inline-newsletter-1-title\" aria-describedby=\"cs-inline-newsletter-1-copy\">\n<div class=\"cs-inline-newsletter__inner\">\n<div class=\"cs-inline-newsletter__content\"> <span class=\"cs-inline-newsletter__eyebrow\"> <i class=\"fa-regular fa-envelope\" aria-hidden=\"true\"\/> The Daily Brief <\/span><\/p>\n<h2 id=\"cs-inline-newsletter-1-title\" class=\"cs-inline-newsletter__title\">The signal, before the noise.<\/h2>\n<p id=\"cs-inline-newsletter-1-copy\" class=\"cs-inline-newsletter__copy\">Start your day with the crypto stories moving markets, decoded by CryptoSlate\u2019s editors.<\/p>\n<\/div>\n<div class=\"cs-inline-newsletter__form-shell\">\n<p class=\"cs-inline-newsletter__form-heading\">One email. Everything that matters.<\/p>\n<p id=\"cs-inline-newsletter-1-privacy\" class=\"cs-inline-newsletter__privacy\">Free to join. Unsubscribe any time.<\/p>\n<p> <i class=\"fa-regular fa-circle-xmark\" aria-hidden=\"true\"\/> <span>Whoops, looks like there was a problem. Please try again.<\/span><\/p>\n<p> <i class=\"fa-regular fa-circle-check\" aria-hidden=\"true\"\/> <span><strong>You\u2019re on the list.<\/strong> Your next Daily Brief is on its way.<\/span><\/p>\n<\/div>\n<\/div>\n<\/aside>\n<p>Most phishing links appeared to have been taken down by the time of that update, according to BitBox, which said its investigation was continuing.<\/p>\n<div class=\"cs-article-embed\">\n<p> <span class=\"cs-article-embed__related-reading\">Related Reading<\/span><\/p>\n<h3 class=\"cs-article-embed__title\">SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft<\/h3>\n<\/p>\n<p> <span class=\"cs-article-embed__arrow\" aria-hidden=\"true\"> <i class=\"fa-light fa-arrow-up-right\"\/> <\/span> <\/div>\n<h2>Keep recovery seeds private<\/h2>\n<p>The warnings concern emails impersonating wallet companies. Trezor&#8217;s reassurance about its wallets does not make following a phishing message safe: its standing security guidance says anyone who obtains a wallet backup, also called a recovery seed, can move the funds.<\/p>\n<p>Trezor tells users never to share that backup and to check official channels if they are concerned about a message or their wallet&#8217;s security. Its guidance also advises avoiding suspicious links and attachments and downloading Trezor Suite only from its official website.<\/p>\n<p>For recipients, the immediate response is to ignore the phishing emails&#8217; instructions and keep recovery words private. Any follow-up about the incident should be checked through the companies&#8217; official channels, rather than through links supplied by the suspicious email.<\/p>\n<\/div>\n<p>Adoption,Featured,Scams,Wallets,Bitcoin,TrezorBitcoin,Trezor#Attackers #exploit #fake #STM32 #vulnerability #alert #target #Trezor #BitBox #holders1789117044<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hardware-wallet makers Trezor and BitBox warned users on Sept. 9 about phishing emails impersonating their brands, urging recipients to avoid the messages&#8217; links and instructions. Trezor said its third-party email provider had been breached and reiterated on Sept. 10 that its wallets remained safe. Trezor identified an email titled \u201cCritical Security Alert: STM32 Entropy Vulnerability\u201d<\/p>\n","protected":false},"author":1,"featured_media":13095,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[6660,5057,6861,91,664,2746,417,6859,39,6014,6860],"class_list":["post-13094","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ethereum","tag-alert","tag-attackers","tag-bitbox","tag-bitcoin","tag-exploit","tag-fake","tag-holders","tag-stm32","tag-target","tag-trezor","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.6 (Yoast SEO v26.6) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders - Crypto News: Latest Cryptocurrency News and Analysis<\/title>\n<meta name=\"description\" content=\"Trezor confirms an email-provider breach and says its wallets remain safe, while BitBox investigates a likely newsletter-provider compromise.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.uk.com\/?p=13094\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders\" \/>\n<meta property=\"og:description\" content=\"Trezor confirms an email-provider breach and says its wallets remain safe, while BitBox investigates a likely newsletter-provider compromise.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.uk.com\/?p=13094\" \/>\n<meta property=\"og:site_name\" content=\"Crypto News: Latest Cryptocurrency News and Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-11T08:57:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/trezor-bitbox-phishing-alert.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"\u884c\u653f\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u884c\u653f\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=13094\",\"url\":\"https:\/\/cryptonews.uk.com\/?p=13094\",\"name\":\"Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders - Crypto News: Latest Cryptocurrency News and Analysis\",\"isPartOf\":{\"@id\":\"https:\/\/cryptonews.uk.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=13094#primaryimage\"},\"image\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=13094#primaryimage\"},\"thumbnailUrl\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/trezor-bitbox-phishing-alert.jpg\",\"datePublished\":\"2026-09-11T08:57:24+00:00\",\"author\":{\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf\"},\"description\":\"Trezor confirms an email-provider breach and says its wallets remain safe, while BitBox investigates a likely newsletter-provider compromise.\",\"breadcrumb\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=13094#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/cryptonews.uk.com\/?p=13094\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=13094#primaryimage\",\"url\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/trezor-bitbox-phishing-alert.jpg\",\"contentUrl\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/trezor-bitbox-phishing-alert.jpg\",\"width\":1280,\"height\":720},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=13094#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/cryptonews.uk.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/cryptonews.uk.com\/#website\",\"url\":\"https:\/\/cryptonews.uk.com\/\",\"name\":\"Crypto News: Latest Cryptocurrency News and Analysis\",\"description\":\"Latest Crypto &amp; Bitcoin News\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/cryptonews.uk.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf\",\"name\":\"\u884c\u653f\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g\",\"caption\":\"\u884c\u653f\"},\"sameAs\":[\"http:\/\/demo3.aiwalls.com\/coinbase\"],\"url\":\"https:\/\/cryptonews.uk.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders - Crypto News: Latest Cryptocurrency News and Analysis","description":"Trezor confirms an email-provider breach and says its wallets remain safe, while BitBox investigates a likely newsletter-provider compromise.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.uk.com\/?p=13094","og_locale":"en_US","og_type":"article","og_title":"Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders","og_description":"Trezor confirms an email-provider breach and says its wallets remain safe, while BitBox investigates a likely newsletter-provider compromise.","og_url":"https:\/\/cryptonews.uk.com\/?p=13094","og_site_name":"Crypto News: Latest Cryptocurrency News and Analysis","article_published_time":"2026-09-11T08:57:24+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/trezor-bitbox-phishing-alert.jpg","type":"image\/jpeg"}],"author":"\u884c\u653f","twitter_card":"summary_large_image","twitter_misc":{"Written by":"\u884c\u653f","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/cryptonews.uk.com\/?p=13094","url":"https:\/\/cryptonews.uk.com\/?p=13094","name":"Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders - Crypto News: Latest Cryptocurrency News and Analysis","isPartOf":{"@id":"https:\/\/cryptonews.uk.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.uk.com\/?p=13094#primaryimage"},"image":{"@id":"https:\/\/cryptonews.uk.com\/?p=13094#primaryimage"},"thumbnailUrl":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/trezor-bitbox-phishing-alert.jpg","datePublished":"2026-09-11T08:57:24+00:00","author":{"@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf"},"description":"Trezor confirms an email-provider breach and says its wallets remain safe, while BitBox investigates a likely newsletter-provider compromise.","breadcrumb":{"@id":"https:\/\/cryptonews.uk.com\/?p=13094#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.uk.com\/?p=13094"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptonews.uk.com\/?p=13094#primaryimage","url":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/trezor-bitbox-phishing-alert.jpg","contentUrl":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/trezor-bitbox-phishing-alert.jpg","width":1280,"height":720},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.uk.com\/?p=13094#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.uk.com\/"},{"@type":"ListItem","position":2,"name":"Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.uk.com\/#website","url":"https:\/\/cryptonews.uk.com\/","name":"Crypto News: Latest Cryptocurrency News and Analysis","description":"Latest Crypto &amp; Bitcoin News","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.uk.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf","name":"\u884c\u653f","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g","caption":"\u884c\u653f"},"sameAs":["http:\/\/demo3.aiwalls.com\/coinbase"],"url":"https:\/\/cryptonews.uk.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts\/13094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13094"}],"version-history":[{"count":0,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts\/13094\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/media\/13095"}],"wp:attachment":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}