Trezor warned customers about phishing emails sent from its legitimate domain after a third-party provider breach, the second third-party security incident affecting its customers in a month.
Trezor warned customers about phishing emails sent from its legitimate domain after a third-party provider breach, the second third-party security incident affecting its customers in a month.
Key Points:
- A breached third-party email provider enabled attackers to send a fraudulent Trezor security warning through the company’s legitimate domain.
- BitBox reported a similar phishing campaign, while official sender details made the fraud harder to identify.
- The earlier ShipMonk breach ultimately affected roughly 80,700 Trezor customers and exposed personal data that could increase the risk of targeted phishing.
Trezor Phishing
A third-party email provider breach let attackers use Trezor’s official domain to distribute a fake warning titled “Critical Security Alert: STM32 Entropy Vulnerability.” The company told users on Sep. 9 that the message was fraudulent and instructed recipients not to click links or follow its directions. Trezor has taken the domain offline.
“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt,” Trezor wrote.
BitBox, a Swiss Bitcoin(BTC) hardware wallet maker, reported a similar phishing campaign circulating under its name on the same day. Crypto commentator Marcello Paz shared screenshots showing a Trezor-branded message with official domain names and signatures, making the email harder to distinguish from routine phishing.
Also Read:Ethereum Volume Jumps 20% While Bulls Push Toward $2,550 Breakout
Ledger Security Context
The use of a legitimate sender domain matters because checking the visible email address alone would not have exposed the fraudulent message. Paz said the email asked customers to update their hardware wallets because of a supposed critical vulnerability that could affect newer devices. The company is investigating the access.
The email breach is separate from a June hardware disclosure involving the TROPIC01 chip used inside the Trezor Safe 7 device.
Ledger’s Donjon security team demonstrated a lab-based laser attack that bypassed the chip’s firmware verification system during controlled testing. Trezor said user funds remained safe.
A 2020 Ledger breach exposed personal information belonging to more than 270,000 customers, including names, email addresses, phone numbers and, in some cases, home addresses. Those scams persisted for years.
Trezor’s latest warning also follows its August disclosure that shipping provider ShipMonk exposed customer information, with about 13,700 customers initially identified before another 67,000 U.S. customers were added on Sep. 4. The disclosed total reached roughly 80,700 customers.
Read Next:Hunter Biden’s LAPTOP Crashes Over 99%, Erases Most Of $200B-Plus FDV In Hours