Trezor Email System Breached in Widespread Phishing Attack
Trezor, a well-known manufacturer of hardware wallets, has fallen victim to a phishing attack. The security breach occurred when cybercriminals compromised Trezor's external email service provider, allowing them to distribute phishing messages using the company's verified domain.
The fraudulent emails claimed that a 'Critical Security Alert: STM32 Entropy Vulnerability' existed, which could compromise the randomness generation process for recovery seed phrases and put stored cryptocurrency assets at risk. However, Trezor immediately issued a warning through its X platform, stating that the email was not legitimate and urging users to avoid interacting with it.
The incident has sparked concerns among security experts, who believe that the timing of the phishing messages was strategically chosen to capitalize on worries surrounding the recent Coldcard security flaw. This vulnerability resulted in cryptocurrency losses exceeding $130 million in Bitcoin. BitBox customers were also targeted by identical phishing emails, indicating a potential broader attack.
Trezor has disabled the affected domain and initiated a comprehensive security investigation. The company has warned users to be cautious when receiving security notifications from wallet manufacturers and to verify all alerts through direct navigation to official company websites.