Trezor Email Provider Hacked, Hackers Send Phishing Emails to Users
Trezor, a popular hardware wallet provider, has been hit by a security breach that allowed hackers to send phishing emails from its official email domain. The fake emails claimed that a 'Critical Security Alert: STM32 Entropy Vulnerability' existed in Trezor devices, which could expose users' recovery phrases and put their funds at risk.
The emails were convincingly written and appeared to be timed to exploit fears around the recent Coldcard vulnerability, which cost users more than $130 million in Bitcoin. BitBox, another hardware wallet maker, also reported receiving similar phishing emails from its users.
Trezor quickly responded by taking down the compromised domain and launching an investigation into how hackers gained access. The company warned users not to click on any links in security-related emails from wallet providers until further notice.