Phishing Attack Exploits Trezor's Email Service Provider Breach
A phishing attack targeting Trezor users exploited a breach in the company's external email service provider, allowing attackers to send convincing emails from legitimate domains.
The scam email claimed that there was a critical hardware vulnerability in Trezor devices, known as the 'STM32 Entropy Vulnerability', which threatened users' funds. However, this claim was false, and the email was designed to lure users into clicking on malicious links.
Trezor has since shut down the malicious infrastructure and is investigating how attackers gained access to its legitimate domain. No confirmed cryptocurrency losses have been tied to the phishing campaign as of publication.