Trezor Owners Targeted by Phishing Emails with Credible Security Warning
A recent phishing attempt targeted owners of hardware wallets from Trezor, a well-known manufacturer in the crypto industry. The attackers sent a convincing email that looked like it came directly from Trezor's genuine sending channel, complete with a warning about a critical security alert and a link to a landing page.
The message claimed that developers had discovered a hardware-level flaw in microcontrollers of the STM32 family, which could compromise the randomness of recovery phrases. This was a credible-sounding threat because it touched on a genuine concern for crypto investors.
However, Trezor quickly issued a statement denying responsibility for the email and warning recipients not to click on any links. The company had the linked landing page taken down and announced an investigation into the breach at their external service provider.
The attackers' goal was to trick victims into entering their recovery phrase on a form, which would have given them access to the wallet's contents. Fortunately, the attack was unsuccessful, but it highlights the importance of verifying email authenticity and being cautious when receiving security warnings.