Hardware wallet maker Trezor alerted its users on Wednesday to a phishing campaign that leveraged a breach of its third-party email provider. The fraudulent emails, disguised as critical security alerts, falsely claimed a vulnerability in STM32 microcontrollers used in Trezor devices could compromise the randomness of recovery phrases. Trezor issued a warning shortly after users began reporting the scam, urging them not to click any links within the suspicious emails. The company has since taken down the malicious domain and initiated an investigation into how hackers accessed its legitimate domain. Security experts, including Casa co-founder and CEO Nick Neuman and Bitcoin security researcher Jameson Lopp, suggested that the breach may extend beyond Trezor, potentially affecting other hardware wallet providers that use similar marketing email services. This incident follows previous warnings issued by Trezor and other hardware wallet manufacturers regarding phishing attempts that exploit user fears about device security, particularly after vulnerabilities affecting Coldcard devices were disclosed. In August, Trezor also reported a data breach at its shipping provider, ShipMonk, which exposed personal information of nearly 81,000 customers, raising concerns about potential use in more sophisticated phishing attacks.
Discussion