Crypto Prices

Trezor Warns Users of Phishing Scam Following Email Provider Breach

11 hours ago
1 min read
6 views

Trezor Alerts Customers About Phishing Incident

Trezor, a prominent hardware wallet manufacturer, alerted its customers on Wednesday about a security incident involving its third-party email service provider. Hackers exploited this breach to send out a fraudulent phishing email that masqueraded as an urgent security notice.

In a post on social media platform X, Trezor cautioned users, stating, “The email titled ‘Critical Security Alert: STM32 Entropy Vulnerability’ does not originate from us and is part of a phishing attempt. We advise against clicking any links within it.”

The company has already disabled the domain implicated in the attack and launched an inquiry to determine how the breach occurred. This phishing email falsely warned recipients that a severe vulnerability had been identified in the STM32 microcontrollers integral to Trezor’s devices, suggesting that one in four devices could be compromised due to potential inadequacies in randomness—an apparent attempt to exploit fears stemming from a recent security failure involving Coldcard that resulted in substantial financial losses.

Community Response and Concerns

Trezor issued its advisory shortly after 4:30 p.m. Eastern Time, although users had started reporting the phishing attempts earlier in the day, believing the communication to be credible given it appeared to originate from a legitimate Trezor email account. Nick Neuman, co-founder and CEO of Casa, expressed concern that this phishing campaign might affect other hardware wallet users, indicating that Bitbox customers reported similar scams.

Neuman remarked on X, “It’s probable that a marketing email provider was compromised. Remain vigilant and be careful with provider emails that include dubious links.”

Echoing these sentiments, Casa’s Chief Security Officer, Jameson Lopp, alerted the community to the risks, emphasizing that the emails from Trezor and Bitbox appeared authentic and not spoofed. He warned on X that no official security advisory had been released regarding the alleged vulnerabilities.

Background on Phishing Attacks

This incident follows an earlier warning from Trezor and another hardware wallet producer, Foundation, regarding phishing attacks that prey on users’ concerns about the security of their devices. In a related issue, Trezor had previously reported a significant breach at logistics partner ShipMonk, exposing sensitive information of nearly 81,000 customers, including names and email addresses, which could facilitate increasingly sophisticated phishing schemes.

Popular