Trezor Warns of Phishing Campaign Exploiting Hardware Wallet Fears
Trezor, a leading manufacturer of Bitcoin wallets, warned its users about a phishing email campaign that exploited fears related to hardware wallet security. The company said hackers breached its third-party email provider and used it to send emails claiming there was a critical security flaw in the STM32 microcontrollers used in some devices.
The fake email claimed an estimated one in four devices were affected, which could leave recovery phrases with insufficient randomness. This sparked concerns related to the recent Coldcard exploit that resulted in over $130 million in lost Bitcoin.
Trezor took down the domain used in the attack and is investigating how hackers gained access to its legitimate domain. The company warned users not to click on any links or take action based on the email, which was sent from what appeared to be a legitimate Trezor email address.