Trezor has warned customers about a phishing email sent after attackers breached one of its third-party email providers.
The email warns about a major Trezor wallet security risk, but the warning is false, says the firm, and it advises recipients not to click links.
Fake email warns of Trezor wallet flaw
The subject line of the phishing email is “Critical Security Alert: STM32 Entropy Vulnerability.”
It almost looks as though the text is trying to trick the recipients into believing their hardware wallets are immediately at risk. Clicking the link may lead unsuspecting victims to a website asking them to provide confidential details of their wallets, etc.
In a post, Trezor said:
The email…is not coming from us, and it’s a phishing attempt.
The company has taken down the domain involved and is investigating how the attackers gained access to a legitimate domain.
Because the email came from a genuine domain, some users might be convinced that it is real. Attentive users usually check the sender’s address before trusting an email, but because it’s an original domain, a fraudulent message may appear real.
Trezor has not revealed the name of the affected email provider, nor has it said how many of its customers received the fraudulent message or whether their details were accessed
In addition, it has not reported any loss of cryptocurrency due to the campaign.
A separate third-party breach
There was a breach some weeks back involving Trezor’s shipping provider, ShipMonk.
This exposed names, email addresses, phone numbers, and delivery addresses, but Trezor later said 67,000 more customers have also been affected in the US.
However, the latest email provider targeted phishing campaign did not come from ShipMonk, and Trezor has neither attributed the incidents together nor claimed that the same attackers were responsible for both incidents.
Customers who received the new email should avoid its links and delete the message. They should also never enter their wallet backup on a website or share it with anyone.
Final Summary
- Trezor says attackers breached a third-party email provider and circulated a fake security warning.
- Trezor has shut down that domain but has yet to reveal the provider used to send out the emails or the number of affected users.





Be the first to comment