Trezor email provider breached as fake wallet security alert spreads

요약:Trezor has warned customers about a phishing email sent after attackers breached one of its third-party email providers. The email warns about a major

Trezor has warned customers about a phishing email sent after attackers breached one of its third-party email providers.

The email warns about a major Trezor wallet security risk, but the warning is false, says the firm, and it advises recipients not to click links.

Fake email warns of Trezor wallet flaw

The subject line of the phishing email is “Critical Security Alert: STM32 Entropy Vulnerability.”

It almost looks as though the text is trying to trick the recipients into believing their hardware wallets are immediately at risk. Clicking the link may lead unsuspecting victims to a website asking them to provide confidential details of their wallets, etc.

In a post, Trezor said:

The email…is not coming from us, and its a phishing attempt.

The company has taken down the domain involved and is investigating how the attackers gained access to a legitimate domain.

Because the email came from a genuine domain, some users might be convinced that it is real. Attentive users usually check the sender‘s address before trusting an email, but because it’s an original domain, a fraudulent message may appear real.

Trezor has not revealed the name of the affected email provider, nor has it said how many of its customers received the fraudulent message or whether their details were accessed

In addition, it has not reported any loss of cryptocurrency due to the campaign.

A separate third-party breach

There was a breach some weeks back involving Trezors shipping provider, ShipMonk.

This exposed names, email addresses, phone numbers, and delivery addresses, but Trezor later said 67,000more customers have also been affected in the US.

However, the latest email provider targeted phishing campaign did not come from ShipMonk, and Trezor has neither attributed the incidents together nor claimed that the same attackers were responsible for both incidents.

Customers who received the new email should avoid its links and delete the message. They should also never enter their wallet backup on a website or share it with anyone.

Final Summary

  • Trezor says attackers breached a third-party email provider and circulated a fake security warning.
  • Trezor has shut down that domain but has yet to reveal the provider used to send out the emails or the number of affected users.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

미 재무부 $60억 채권 바이백…시장, 높은 관심 안 함

다음

트럼프, 유가 하락 시점 언급…브렌트 5월 최고치 경신