Attackers breached a third-party email provider used by Trezor and sent customers a fake security alert about a hardware wallet flaw. Trezor says the message is a phishing attempt, has taken down the domain involved, and has not disclosed the provider's name or how many customers received it.
Trezor has warned customers about a phishing email sent after attackers breached one of its third-party email providers. The message claims a critical flaw threatens users' hardware wallets, but the company says the warning is false and is urging recipients not to click any links inside it.
Fake alert cites a wallet vulnerability
The phishing email carries the subject line Critical Security Alert: STM32 Entropy Vulnerability, wording that almost looks as though it is trying to convince recipients their hardware wallet is immediately at risk. Clicking the embedded link can lead victims to a site that asks for confidential wallet details. According to Trezor: "is not coming from us, and it's a phishing attempt".
Because the email was sent from a genuine domain, some recipients may have been convinced it was authentic even though attentive users would normally check a sender's address before trusting such a message. Trezor has taken down the domain involved and is investigating how attackers gained access to it. The company has not named the affected email provider, has not said how many customers received the fraudulent message, and has not confirmed whether any customer data was accessed. It has also reported no loss of cryptocurrency tied to the campaign.
A separate breach at Trezor's shipping partner
The phishing incident follows an earlier breach weeks ago involving Trezor's shipping provider, ShipMonk, which exposed customer names, email addresses, phone numbers, and delivery addresses. Trezor later said the breach expanded to affect 67,000 more customers in the US.
However, the new email provider breach did not originate from ShipMonk, and Trezor has not attributed the two incidents to the same attackers. Customers who receive the phishing message should delete it and avoid its links. Trezor is reiterating that a wallet backup should never be entered on a website or shared with anyone.
Source: AMBCrypto
Trading involves risk.