Trezor's Email Provider Breached in Widespread Phishing Scam
Trezor, a leading manufacturer of Bitcoin wallets, has fallen victim to a phishing scam. Hackers breached Trezor's third-party email provider and used it to send fake security alerts to users.
The malicious emails claimed that an STM32 hardware flaw had weakened recovery phrases on some Trezor devices, causing widespread panic among users.
Trezor quickly responded by issuing a statement calling the email fraudulent and warning its users. The company also took down the domain used in the attack and is investigating how hackers gained access to its legitimate domain.
Casa co-founder and CEO Nick Neuman speculated that the campaign may extend beyond Trezor, as several Bitbox users have reportedly received similar phishing emails from what appeared to be a legitimate email address.