A Fake STM32 Alert Hit Trezor and BitBox Inboxes on Sept. 9. Here's What Actually Broke.
Trezor and BitBox both warned users about phishing emails on Sept. 9 after third-party email vendors got compromised. The hardware held. The mailing lists didn't. And the fake subject line was aimed at people who read firmware notes.
I've deleted a lot of phishing emails. Most are obvious. A prince, a fake Coinbase login, some wallet that needs "revalidation." Delete, delete, delete.
The ones that landed in Trezor and BitBox inboxes on Sept. 9 were a different species. They arrived through the companies' real domains, signed by real mail servers, with a subject line that read: "Critical Security Alert: STM32 Entropy Vulnerability."
That's not a random shot in the dark. That's a sniper round aimed at people who know what STM32 means.
What actually broke
Neither company lost a wallet. Neither lost a seed. What got compromised was the newsletter and email apparatus both firms rent from third parties, the same way most of us rent our calendars and our payroll.
Trezor said a third-party email provider had been breached, then repeated that on Sept. 10 for anyone who missed it the first time. BitBox said its preliminary review found it very likely that its newsletter provider had been compromised, and pointed out that other Bitcoin companies using the same vendor had been hit too.
Both pulled the phishing domains. BitBox reported that most of the links were already dead by the end of its Sept. 9 update. Fast incident response, genuinely.
But focus on the mechanics, because this is where it gets interesting.
STM32 is a microcontroller family from STMicroelectronics, and it sits inside a lot of hardware wallets, Trezor's included. If a real entropy flaw existed in that chip, the consequences would be catastrophic. Weak randomness means predictable keys. Predictable keys mean your coins belong to whoever ran the math first.
So the subject line wasn't decoration. It was a targeting filter. The attacker didn't want a click from a random retiree in Ohio. They wanted a click from someone who owns a cold wallet, reads firmware release notes, and knows the difference between an entropy bug and a UI patch. That's a small list. Somebody built a message specifically for it.
And here's the part worth sitting with. The mail passed authentication because it came through legitimate infrastructure. Your spam filter doesn't evaluate whether a sentence is true. It evaluates whether the envelope looks right. Naturally.
Which raises the obvious question. If the silicon is hardened, the firmware is signed, and the seed never touches a network, then what's the perimeter? The subscription list. The marketing stack. The contractor nobody in security owns.
Why wallet makers keep getting hit
The self-custody pitch has always been simple. Not your keys, not your coins. After a decade of exchange blowups, that pitch worked. Millions of people moved holdings into devices they control.
The trade is real and it's uncomfortable. Custody didn't get safer. It got closer. Now the attack surface is the person holding the device, and that person's inbox.
This isn't hypothetical. A breach exposing 40,000 customer records at another hardware wallet brand was irritating. The escalation that followed, with hardware wallet attacks tied to thefts running into the $100 million range, was something else. A leaked email list is a directory of people who already own crypto and already have a reason to trust a particular brand name.
That's a lead list. And the economics are lopsided in a way that should make every security team uncomfortable. Sending 100,000 convincing emails costs a few hundred dollars. Draining one cold wallet can be life-changing money. The attacker only needs one click out of a hundred thousand. Which seems like an even stronger argument for treating your email vendor as part of your threat model instead of part of your growth team.
Who wins here? Attackers, marginally. And honestly, the wallet brands get a free reminder cycle out of it, which is grim but true. Who loses? The shared newsletter vendor, whoever they're, and every user who clicked before the warnings went out.
What I'd actually do
Spare me the roadmap. Here's the short version.
No legitimate wallet company will ever need your recovery seed. Not support, not a security audit, not a firmware update, not an emergency. The seed is the wallet. Trezor's own guidance says as much. Anyone holding the backup can move the funds. So the only correct response to a request for those words is silence and a delete key.
Second, a real vulnerability announcement doesn't arrive as an email asking you to act within the hour. Real ones get coordinated disclosure, a published advisory, and a signed firmware update you install through the official app. Urgency is the tell. It's always the tell.
Third, stop trusting links. If you're worried about your device, open the app, or type the company's address by hand. And if you're running serious holdings, use a separate email address for crypto vendors, one that never touches your daily inbox.
And if you already clicked, don't spiral. Move. Generate a fresh seed offline on a new device and move your funds. Today. Not after the next newsletter goes out.
I've seen enough marketing stacks described as growth infrastructure to know exactly how they get funded. Cheaply, off to the side, by people whose job titles don't include the word risk. Two of the most paranoid companies in this industry spent years hardening silicon, and then handed the front door to a mailing list provider.
The wallets held. That's the good news. The caution is what needs the update.