Crypto
Home›Crypto›Market Structure›Trezor flags phishing emails sent from its official do…
Trezor flags phishing emails sent from its official domain
The hardware wallet maker said a breach at a third-party email provider allowed phishing to be sent from its domain, and it has taken the domain down while investigating how the attack worked.
Trezor warned users that phishing emails were sent from its official domain after a breach at a third-party email provider, according to The Block. The company cautioned that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” was not sent by Trezor and advised recipients not to click links.
Trezor said it has taken down the domain and is investigating how attackers were able to use its official domain for the phishing messages. It also warned users to recognize the communication as fraudulent.
The Block notes the warning comes after a separate prior incident involving Trezor and its shipping provider, ShipMonk, which exposed personal information of customers. Trezor previously said about 13,700 customers were affected, and later said another 67,000 U.S. customers were also impacted by the same breach.
The Block also reported that BitBox, another Swiss bitcoin hardware wallet maker, saw similar phishing activity on the same day. Separately, it cited earlier research by Ledger’s Donjon team on a hardware vulnerability in a chip used inside the Trezor Safe 7, with Trezor saying at the time that no user funds were at risk.
Latest closeBitcoin $78,304.79 ▼0.2%