You Got An Email From "Trezor" This Week?
It landed in 347,000 inboxes with a screaming subject line: "Critical Security Alert: STM32 Entropy Vulnerability." It came from Trezor’s own domain. It told you to download an app and enter your wallet backup — your seed phrase, the master key to every satoshi you own.
It was a scam. And 2,500 of you already clicked.
The Facts: They Don’t Hack The Device. They Hack YOU.
This week Trezor disclosed that criminals broke into Brevo — the third-party platform the hardware wallet maker uses to send newsletters — and used Trezor’s own domain name to blast phishing emails to 347,000 customers.
The bait was tailored to panic you: a fake alert about the exact "entropy vulnerability" that’s been draining Coldcard wallets all year. A malicious link. An app to "download." A form asking for your recovery phrase.
Trezor’s warning was blunt: "Our third-party e-mail provider has been breached… it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating."
They killed the domain at DNS level within 20 minutes. Too late — 2,500 people had already clicked. Trezor insists "no other Trezor system was touched," then casually adds that the breached addresses "might be potentially used for other phishing attacks in the future."
Read that again: the attackers now hold the email addresses of 347,000 hardware wallet owners. It’s a loaded gun pointed at your paranoia, and it doesn’t need to be re-aimed.
This is the THIRD Trezor data incident this year. Last month it was the ShipMonk fulfillment breach — first 11,742 customers exposed, then another 67,000 Americans’ names, emails, phone numbers and home addresses handed to anyone willing to pay.
And Trezor isn’t alone. Ledger’s payment processor was breached this year and weaponized into phishing campaigns. SafePal leaked 39,798 customer records. Year after year, the hardware wallet industry can’t protect the one thing it’s guaranteed to collect: your identity, your address, your trust.
Why This Is Your Problem
Think about what the scammers actually did here. They didn’t break the Trezor. They didn’t crack the secure element. They didn’t steal a single private key. Why would they? The device is the one wall they can’t get through — so they went around it, straight at the human holding it.
The email wasn’t generic spam. It weaponized a real, terrifying story — the weak-entropy attacks that emptied real wallets — and used it as a lever to get you to type your seed phrase into a fake app. Fear is the phishing hook. Your recovery phrase is the prize.
That’s the uncomfortable truth the hardware wallet industry won’t say out loud: your coins are safe on the device, but your wallet backup — written on paper, typed into laptops, photographed for "safekeeping" — is the softest target in all of Bitcoin. Once you enter those 12 or 24 words into anything that isn’t the device itself, the encryption might as well not exist.
The "unhackable wallet" story was always half true. Nobody has to hack the wallet. They just have to hack you.
The Love Is Bitcoin Takeaway
Here’s the rule that would have saved every one of those 2,500 people: a hardware wallet will never ask you for your seed phrase. Ever. Not in an email, not in an app, not in a "security audit," not in a panic alert. If anything asks for your backup, it’s a thief wearing a costume.
Learn how Bitcoin wallets actually work — who holds what key, and why the seed phrase is the whole game. Verify every address on the device screen. Slow down. That’s the entire difference between self-custody and self-destruction.
And when you’re ready to buy real security, do it like everything else in Bitcoin: on your own terms. Get proper hardware from Bull Bitcoin and use coupon LOVEISBITCOIN — no middlemen deciding what’s good for you, and honest tools reviewed by people who actually hold their own keys.
Because the scammers already bought your email address. Don’t hand them your coins too.
The Only Question That Matters
If a hardware wallet vendor can’t even protect its mailing list — after three data incidents in one year — how much of your security are you willing to leave in anyone’s hands but yours?
This article is for education only and is not financial advice.