Verify, Then Trust
This afternoon two emails from Trezor Security landed in my inbox, forty minutes apart, from two different addresses at the same domain. Subject line on both: “Critical Security Alert: STM32 Entropy Vulnerability.” The first arrived at 1:52 and I did not notice it until the second one showed up at 2:33. They said a hardware flaw in the chips meant some recovery phrases were generated with as little as 40 bits of entropy, that roughly one in four devices was affected, and that I should check whether mine was one of them. ...