Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
Following the Coldcard vulnerability disclosure, we're already seeing an increase in phishing attempts.
Stay alert for scams ⚠️
• Never share your wallet backup, aka recovery seed (12/20/24 words)
• Only enter your wallet backup directly on your Trezor device during recovery
• Trezor will never contact you asking for your wallet backup
• Never follow wallet-migration instructions from unsolicited emails, messages or phone calls
Trezor devices are not affected by the Coldcard incident.
The Coldcard bug explained in simple terms:
Normally, a hardware wallet generates your 12 word seed phrase using true randomness.
Think of it like a lottery with roughly 340 undecillion possible tickets (that’s a 340 followed by 36 zeros). Every ticket has an equal chance of being picked, making the odds of guessing your seed essentially zero.
The bug didn’t shorten the 2,048-word BIP-39 word list. It changed how the wallet picked the words.
Instead of choosing from the entire lottery, the wallet kept picking from the same tiny corner because the “random” numbers were partially predictable from things like the device’s ID and timing.
Imagine that instead of 340 undecillion possible combinations, your wallet accidentally chose from only a few billion. That’s still a huge number, but astronomically smaller than what Bitcoin’s security is designed to provide.
Your seed phrase still looked completely normal. The words came from the same 2,048-word list. Nothing looked suspicious.
But for an attacker, the search space became millions of trillions of trillions of times smaller.
Trezor users: your funds are safe.
The recent Coldcard issue is limited to their own custom firmware and how some of their devices generated randomness. Trezor does not share that code.
We have always mixed multiple independent sources of randomness together (device hardware + host + secure elements on newer models).
We are truly sorry for everyone who has lost bitcoin.
Stay safe.
Read more on how Trezor generates entropy here: https://t.co/Nj6xveBQJk