Trezor has warned customers about a phishing email campaign following a breach of one of its third-party email providers. The company confirmed the fraudulent message is not from Trezor and advised recipients not to click any links in the email.
The phishing email carries the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and falsely claims a major security flaw affecting Trezor hardware wallets. Recipients who click the link may be directed to a fraudulent website designed to harvest sensitive wallet information.
Because the email originated from a legitimate domain, some users may have initially believed it was authentic. Trezor has taken down the compromised domain and is investigating how attackers gained access.
Trezor has not disclosed the name of the affected email provider, the number of customers who received the phishing message, or whether customer data was accessed. The company also reported no cryptocurrency losses from the campaign.
The phishing campaign is separate from a breach of Trezor's shipping provider, ShipMonk, which occurred weeks earlier. That incident exposed customer names, email addresses, phone numbers, and delivery addresses. Trezor stated that 67,000 additional U.S. customers were affected by the ShipMonk breach. The company has not indicated that the same attackers were responsible for both incidents.
Trezor advised customers who received the phishing email to delete it and avoid clicking any links. The company also reminded users never to enter their wallet backup phrase on any website or share it with anyone.


