Fake Trezor Warning Claims 25% of Devices Are Vulnerable in Latest Phishing Campaign

4 hours ago 1



Trezor users are being targeted again with sophisticated phishing messages. Hardware wallet maker Trezor said its third-party provider was breached and warned users that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” was not sent by the company but was instead a phishing attempt. The company urged users not to click any links. Trezor Phishing Scam In an update on X, Trezor said it had taken down the domain and was investigating how hackers accessed its legitimate domain. The phishing message in question attempted to convince users that a serious security flaw has been found in STM32 microcontrollers used in its devices. According to the fabricated warning, STM32 microcontrollers could generate recovery phrases without enough randomness, potentially putting users’ funds at risk. The email further claims that as many as 25% of devices may be affected. The issue may not be limited to Trezor users, according to Casa CEO and co-founder Nick Neuman. He noted that reports of similar messages have surfaced among people using the BitBox device as well. This isn’t the first time a third-party partner connected to Trezor has suffered a security breach. In August, the p...

Read Entire Article