Skip to main content
Back to news
Safety

Attackers Use Fake STM32 Chip Vulnerability Alert to Target Hardware Wallet Users

(21 days ago) · 1 source · Summarized by CryptoBipto — how we make this

Attackers have reportedly been circulating a fabricated security advisory about a vulnerability in STM32 microcontrollers to target users of Trezor and BitBox hardware wallets. The fake alert appears designed to trick wallet holders into taking actions that could compromise their funds. Users are being warned to verify any security notices through official channels before responding.

WHY IT MATTERS

Hardware wallets are physical devices that store cryptocurrency offline, making them one of the more secure ways to hold digital assets. They use small computer chips — in this case, STM32 microcontrollers — to process transactions securely. Think of a hardware wallet like a safe for your crypto: the chip is part of the lock mechanism. In this attack, scammers are essentially sending fake letters claiming the lock on your safe is broken, hoping you will open the safe and hand over its contents while trying to "fix" the problem. This is a form of social engineering, where attackers manipulate people rather than breaking technology directly. The key lesson is that legitimate security warnings come from official sources, and users should always verify alerts by going directly to the manufacturer's website rather than clicking links or following instructions from unsolicited messages.

STM32 microcontrollers, manufactured by STMicroelectronics, are widely used chips found in many hardware wallets including models from Trezor and BitBox.

Read the full analysis with a CryptoBipto membership

Members can read the full analysis of every story, not just the headline.

Get started

RELATED

Hardware WalletsSocial EngineeringPhishingCybersecurity