Possible E-mail scam

I just received this email… The from address seems legitimate, but the verificacion site asks for private seeds, so this sound like a scam to me.

The general subject is STM32 Entropy Bug Identified

Please, if someone from Trezor can confirm.

6 Likes

Just came here to check about this, as I just recieved it too. According to Claude it’s a pishing email, beware and do not click on the link.

2 Likes

I received an e-mail with exactly the same subject line. I created a support ticket in the chat and forwarded it via e-mail to trezor’s support. I am very concerned. Where did they get my e-mail address from? I thought the hackers “only” got data of users from 3 years ago. How can they use the exact same tezor help e-mail address as a sender? It looks so legit it’s scary.

2 Likes

I am concerned too, but according to Claude:

What the search turned up:

  • Trezor has publicly stated a “Critical Vulnerability Notice” phishing email circulating is not from Trezor, and pointed to its false urgency and instructions to act outside official channels as the giveaways.

  • A separate report describes users receiving a phishing email claiming a “critical entropy vulnerability,” alleging vulnerable firmware used a weak RNG instead of the hardware TRNG, and that this could reduce seed entropy from 128 down to 40 bits — this is word-for-word the scenario your email describes, just reused as a template.

  • Trezor has also confirmed a real prior incident where its contact-form system was abused so that attacker-submitted support requests triggered legitimate-looking automated replies, and separately that its newsletter subscriber database was accessed and misused by a third party to send malicious emails.

  • The 40-bit entropy/STM32/weak-RNG story is actually lifted from a real 2026 Coldcard (different company) firmware bug — not Trezor at all. The scammer took a real incident from a competitor and rebranded it as Trezor’s.

3 Likes

I also got the same mail and have just signed up to report.

For Trezor support: I also opened itcket 261688 for this.

Checking the email header it seems like it’s legitim and comes from Trezor! Citing:

Return-Path: <[email protected]>
X-Original-To: (my email address redacted)
Delivered-To: (my email address readacted)
Received: from ``mailing.trezor.io`` (``mailing.trezor.io`` [172.246.19.223])
by my_mailserver (Postfix) with ESMTPS id 5A162A891
for (my email address redacted); Wed, 9 Sep 2026 21:52:29 +0200 (CEST)

There’s a link in the mail, which in my case is begins with this:

r.mailing.trezor.io\mk/cl/f/sh/ 

(change the backslash to slash, the forum engine did not let me post even the shortened link)

…and it’s already suspicious for Firefox for the 2nd attempt, got this error:

Error Code: SSL_ERROR_NO_CYPHER_OVERLAP

It workerd for the 1st time and I could download an “offline” HTML file to check the seed phrase, LOL.

3 Likes

This definitely looks like a scam.

Here’s the code snippet from the “offline” HTML the page instructed me to download and use it to check my seed phrase.

It would post the data to Telegram.

The only question that remains is: how could they use the seemingly official Trezor mailserver to send this mail and how could they get hold of my alias I only used at Trezor’s site?

5 Likes

I’m glad my browser didn’t open the link, which automatically led me to think it was indeed a scam.

1 Like

Received a letter yesterday and email today. Both are using Trezor dot IO website link. Letter seemed like a scam except for the Trezor dot IO link. The email looks real.

3 Likes

Can someone at Trezor confirm this? I’ve just gor the same email.

2 Likes

Yes we urgently need trezor to come out with a statement. I need to know where and how they got my e-mail address and what other data they may have. 2nd how on earth can they use trezor’s legit help e-mail address

2 Likes

I got the email as well. I clicked on the email link but did not proceed any further due to them using the word crackable. Created a phising ticket and they confirmed it was a scam. I just need to know if I am good cause I did click the email link?

1 Like

Just received a similar email with subject “Critical Security Alert: STM32 Entropy Vulnerability“.
I think it is a scam, but it looks very, very legit.
A couple of days ago received a letter postmarked in California, but describing similar “issues”. The letter had a qr code by using which I could “safely transfer wallets.”

Yes, agree, I’d like Trezor to say something. I don’t remember receiving this much sh$#@t .Thanks!!

3 Likes

I got one too. Came here to see what’s up. Looks like it came from a legit domain, and I even typed it in just in case they used one of those letters that looks very close to another letter. The link leads to the real Trezor domain, so how could this be a scam?

2 Likes

I’ve just received the same email. Definitely need Trezor team to step in here.

2 Likes

I also received the same email. It definitely looks legit, and includes this:

“NEVER enter your recovery phrase on a website or share it with anyone, and only check for updates on official Trezor channels.

We are deeply sorry to the community and those affected.

I agree with others concerns, we need Trezor to issue a statement urgently.

1 Like

I also received a similar email, but what really upset me was that it was sent from a legitimate IP address. The email headers show positive checks for SPF, DMARC, and DKIM rules, making the email appear legitimate. The link inside it redirects to a domain under trezor dot io. So, I decided to click on the link and see what would happen.

The click took me to a browser where it said that the link wasn’t working due to issues on the web server. I have a feeling that Trezor, the company behind Satoshi Labs, has disabled their email redirect servers. It seems they might have been hacked, and emails are being sent from their legitimate servers.

What’s concerning is that the letter states that this Trezor team can supposedly determine whether a wallet is problematic or not based on the xpub key.

Do not enter your xpub keys, as doing so would give malicious actors access to know how much money you have.

6 Likes

I just got two more copies of this email lol

1 Like

The e-mail looks veeeeery legitimate to me, but the urgency, plus giving your seed to check if you’re affected make me think this is a scam. I get a second copy, so it’s likely the e-mail list is leaked from somewhere…

Less experienced crypto user may be scamed, a quick warning is very important

2 Likes

I just received the same email. I was checking the Main support website, but there was no information. I am glad the forum was confirming this phishing attempt. It did state Trezor would also be contacting affected users directly as well. That sounds like a compromised mailing list and a more targeted attack to come. I did also receive a Ledger attempt this week-although I do not own their device.

Me too. Signed but suspicious. A search for the email subject on the trezor website yields no results.

1 Like