Trezor Users Targeted by Phishing Emails with Critical Chip Security Warning
The hardware wallet manufacturer Trezor has been targeted by phishing emails that appear to be critical chip security warnings. According to Trezor, hackers breached their third-party email provider and sent out fake emails with a link to a website claiming to address an 'STM32 entropy vulnerability'. The STM32 is a family of small chips used in Trezor devices.
The phishing campaign was reportedly triggered by a data breach at ShipMonk, the company that handles Trezor's shipments. On September 4, the number of affected users exceeded 80,000. In addition to user names, phone numbers, and addresses, some of the leaked data included encryption keys.
Trezor has since removed the domain used in the phishing campaign and is investigating how hackers gained access to their legitimate domain. The company assured users that no sensitive information was compromised during the attack.
A similar incident occurred at SafePal last month, where around 40,000 user data were leaked. This recent attack serves as a reminder of the importance of security measures for cryptocurrency users.