Trezor Warns of Phishing Scam After Hackers Infiltrate Email Provider
Trezor, a hardware wallet manufacturer, issued an alert to users after hackers infiltrated their third-party email provider and used it to send phishing emails disguised as critical security warnings.
The fake email, which appeared to be from Trezor's legitimate email address, claimed that the company's engineers had discovered a 'critical hardware-level vulnerability' in the STM32 microcontrollers used in their devices. It falsely stated that the flaw affected about one in four devices and could leave recovery phrases with insufficient entropy, potentially exploiting fears related to the recent Coldcard exploit that cost users over $130 million in Bitcoin.
Trezor quickly issued a statement labeling the email as fraudulent and warning users, but this came after several users reported receiving the phishing email from what appeared to be Trezor's legitimate email address.