Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning

1 week ago 9



On Wednesday evening, owners of a hardware wallet found an email in their inbox with the subject line “Critical Security Alert: STM32 Entropy Vulnerability”. The message looked like a security warning from the manufacturer Trezor, and it arrived through that company's genuine sending channel. Trezor made clear the same evening that the message had not come from it. That removes the piece of advice which tops almost every guide: look at the sender address. This article explains how to recognise a forged security warning when the technical authenticity checks in your mail client all report green, and which four minutes of work protect you from the most expensive mistake a crypto investor can make. What Happened on September 9: A Warning Email Through the Genuine Channel Trezor said on its account on X on September 9, 2026: “Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link.” According to Decrypt, the post went live at around 4:30 pm US Eastern time, shortly after 10:30 pm in Germany. Recipients had already been reporting the message for hours. What sets this apart fr...

Read Entire Article