Trezor Users Hit by Sophisticated Phishing Campaign
Trezor, a leading hardware wallet maker, warned its users on September 9 that attackers had launched a phishing campaign targeting crypto holders. The fake email claimed to be from Trezor and posed as a critical security alert about a hardware flaw in the STM32 chips inside Trezor devices.
The message falsely stated that this flaw could weaken recovery phrases, which are used to restore access to funds in case of loss or theft. Trezor promptly took down the domain behind the campaign and assured users that their keys, wallets, and recovery backups were not exposed.
This is not an isolated incident; similar scams have targeted users of other hardware wallet companies like Ledger and MetaMask in the past. In 2022, attackers exploited Trezor's MailChimp newsletter list to phish its customers.