No, the Trezor STM32 entropy email is not real. The message titled “Critical Security Alert: STM32 Entropy Vulnerability” is a phishing lure sent on 9 September 2026 through Trezor’s compromised Brevo account. Trezor says it did not send it, the device defect it describes does not exist, and the only risk is whatever a reader types into the attacker’s page.

That is the whole answer. What follows is the evidence, because a reader asking whether the Trezor STM32 entropy email is real deserves to see why the answer is no rather than take our word for it.

Is the Trezor STM32 entropy email real? What it says, and who sent it

All known copies carry the same subject line, per The Register, and the body tells recipients that an estimated one in four Trezor devices has a “hardware factory defect” producing “critically low 40-bit entropy”. Those figures are the attacker’s. They are not a measurement, a bulletin or a disclosure, and the email’s purpose is the next line: it asks recipients to share their wallet backup. The Crypto Times reports that some variants of the landing page asked for an xPub instead.

Trezor’s account, given to The Crypto Times, is that the email went to approximately 347,000 newsletter subscribers, that it was detected at about 21:30 CEST through an internal alert, and that Brevo’s sending logs confirmed the messages left through Trezor’s own account. Trezor’s first public warning on X went up at 20:37 UTC, with a follow-up at 22:20 UTC, and the company says it took down the campaign’s domain. The Crypto Times adds that Trezor has not published any product advisory matching the STM32 claim; that sentence is the outlet’s, and we have not found one either.

Why the Trezor phishing email passed the checks

Recipients told The Crypto Times that the sender name was “Trezor Security”, the From field was help@trezor.io and the Return-Path was mailing.trezor.io. The Register says people sharing copies saw it as from mailing@trezor.io. We report both as reported. Either way the message travelled through Trezor’s real newsletter infrastructure, so SPF, DKIM and DMARC passed. Those checks answer one question: did this server send this? They cannot answer the question that mattered on 9 September, which is whether the account on that server was in the right hands.

The same attacker, three companies, one table

This is the part the single-vendor write-ups leave out. Brevo, formerly Sendinblue, said in a statement quoted by The Register that a security incident “allowed an attacker to access 120 Brevo accounts” and that the attacker used them to send phishing to those clients’ contact lists. Three of the affected clients have spoken publicly. This desk read the three reports below on 11 September 2026; the recipient count is Trezor’s, the account count is Brevo’s, and neither is independently confirmed in the reports we read.

CompanySubject line or lureWhat it asked forSender as reportedRecipientsSeed entropy, per a published source
Trezor“Critical Security Alert: STM32 Entropy Vulnerability”Wallet backup; some variants an xPubhelp@trezor.io, Return-Path mailing.trezor.io (Crypto Times); mailing@trezor.io (Register)About 347,000 newsletter subscribers, per TrezorFirmware source: 32 bytes of device entropy hashed with host entropy; seed kept at 128-256 bits
BitBox (Shift Crypto)“Critical Security Alert: Microcontroller Entropy Bug Identified”Entropy lure, near-identical to Trezor’s, per The RegisterNot stated in the reports we readNewsletter subscribers; no count in the reports we readNot read for this piece
CoinTrackingRefresh your API keysAPI-key reset via a linkNot stated in the reports we readUsers; no count in the reports we readNot applicable
Brevo itself120 accounts accessed, per its statementAttacker sent phishing to clients’ contact listsNot applicableNot applicableNot applicable

The Register quotes BitBox’s X post: its preliminary review found it “very likely” that the newsletter provider was compromised, multiple Bitcoin companies sharing the provider were hit, it had reported the phishing domains, and most links appeared to have been taken down. CoinTracking named Brevo directly; since it sells no hardware, its lure was an API-key refresh rather than an entropy scare. Brevo’s follow-up, as quoted by The CyberSec Guru on 10 September, is that most of the 120 accounts showed no suspicious activity, that the unauthorised access was fully closed at 11:30 CEST that day, and that a full post-mortem would follow. We had not read a post-mortem when this was written, and cannot say whether one has been published.

Do Trezor devices have a 40-bit entropy problem?

Not according to the code Trezor publishes. The reset_device routine in trezor-firmware draws 32 bytes (256 bits) from the device’s random source and halts on an invalid result. It then asks the host for entropy, refuses any that is shorter than the seed strength requested, hashes the two together with SHA-256 and keeps only as many bytes as that strength needs: 128, 192 or 256 bits for a BIP-39 seed, 128 or 256 for a Shamir backup. We are describing what the source says, not what any individual unit did; but the shortest seed this routine will produce is 128 bits, not 40, and no advisory from Trezor that we have found says otherwise.

The number 40 was not chosen at random. A genuine entropy advisory landed on a different vendor this summer, and our Trezor Safe 7 against Coldcard Q review walked through it. A real advisory names affected models and firmware versions, is published on the vendor’s own domain and never asks for your backup. Compare the Ledger bulletins from late August: three defects, three version numbers, and nothing to type. The lure borrowed the vocabulary of a real disclosure and left out every one of its properties.

Did Trezor get hacked in September 2026?

The devices, no. Trezor’s account to The Crypto Times is that the Brevo account held only opt-in newsletter email addresses, no passwords, no wallet data, and that it cannot confirm whether the list was exported, so it is treating all 347,000 addresses as known to the attacker. That comes three weeks after the ShipMonk courier breach; The Register reports that Trezor confirmed on 4 September the affected total had risen to 80,000. If you are on either list, expect more email, and expect it to look better each time.

What to do if you received it

Nothing, other than delete it. Do not click the link, do not “verify” anything, and if you already opened the page and typed your recovery phrase, treat that wallet as compromised and move funds to a new seed made on the device. Trezor’s own instruction, quoted by The Register, is “Never enter your wallet backup anywhere.”

The questions people are asking

Is the Trezor STM32 entropy vulnerability real? No. Trezor said on 9 September 2026 that the email was a phishing attempt sent through its breached third-party email provider, and The Crypto Times reported that Trezor has not published any product advisory matching the STM32 claim. The one-in-four-devices and 40-bit-entropy figures are the attacker’s text, not a finding about any Trezor device.

Did Trezor get hacked in September 2026? Not the devices, and not Trezor’s own systems on the account it has given. Per Trezor’s statement to The Crypto Times, attackers accessed its Brevo newsletter account, which held only opt-in subscriber email addresses, and used it to send the lure. Trezor says no passwords or wallet data were stored there.

Why did the Trezor phishing email pass Gmail’s checks? Because it was sent through Trezor’s real newsletter infrastructure. Recipients told The Crypto Times the From field was help@trezor.io with a Return-Path of mailing.trezor.io, so SPF, DKIM and DMARC all passed. Authentication checks confirm which mail server sent a message; they cannot tell you whether the account behind that server was in the right hands.

What was breached at Brevo? Brevo, formerly Sendinblue, said in a statement quoted by The Register that a security incident allowed an attacker to access 120 Brevo accounts and use them to send phishing emails to those clients’ contact lists. Per The CyberSec Guru’s 10 September update, Brevo says the access was fully closed at 11:30 CEST that day and promised a full post-mortem.

Was BitBox affected by the same phishing email? Yes, by a near-identical one. The Register reported that BitBox shared an image of an email titled Critical Security Alert: Microcontroller Entropy Bug Identified, and that BitBox said on X its newsletter provider had very likely been compromised, that other Bitcoin companies sharing the provider were hit, and that it had reported the phishing domains.

The briefing

The seed-phrase rules do not change because the sender looks right. The recovery phrase is never typed into a keyboard, never photographed, never stored in a cloud, never given to support, and never “verified” on a web page, whatever the subject line says. A newsletter account is the softest thing a wallet maker owns, and this week showed what happens when one is taken. Crypto assets remain high-risk however carefully you hold them, self-custody means self-responsibility, and the safest reading of any security email is the vendor’s own site, opened by hand, not the link in front of you.