Trezor Warns Users of Phishing Attack via Email Provider Breach
- Trezor’s third-party email provider was breached, leading to phishing emails sent to users.
- The phishing email falsely claimed a hardware flaw in STM32 microcontrollers affecting Trezor devices.
- Similar phishing attempts targeted BitBox users, suggesting a broader compromise of hardware-wallet email providers.
- Nick Neuman and Jameson Lopp warned that the compromised emails were not spoofed and advised caution.
Trezor alerted its users about a phishing scam exploiting fears of security vulnerabilities in their devices, following a breach of their third-party email provider. The fraudulent emails claimed a critical flaw in STM32 microcontrollers, similar to recent concerns over Coldcard exploits.
This incident highlights the ongoing risks associated with using external service providers for communication and the importance of verifying any unexpected security alerts directly with the company involved. (Source)