Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack

2 hours ago 3



If a message titled "Critical Security Alert: STM32 Entropy Vulnerability" landed in your inbox this week, apparently from Trezor, telling you that one in four devices shipped with a defective chip and inviting you to run an entropy check in your browser, stop. Do not click anything in it. Trezor did not send it.The company confirmed on Wednesday that attackers had gotten into its email infrastructure and used it to blast a fake security warning to customers. The email is a seed harvester dressed up as an apology, and it is one of the more convincing phishing attempts the hardware wallet space has seen in years.What Does the Fake Trezor Security Alert Actually Claim?The email opens with the tone of a company confessing to a disaster. It claims Trezor's engineering team found a hardware-level defect in the STM32 microcontrollers inside its devices, that the flaw was baked in at the factory, and that roughly one device in four is affected. It says the bug produces recovery phrases with as little as 40 bits of entropy, leaving seeds open to brute-force cracking.It then does something clever. It tells the reader never to enter a recovery phrase on a website or share it with anyone. Two...

Read Entire Article