Market Incident

Public · Developing

Trezor's email provider was breached, and attackers sent fake emails from real Trezor email addresses. The fake email is titled "Critical Security Alert: STM32 Entropy Vulnerability" and claims a hardware defect in Trezor devices. Remember that wallet vendors will never ask

Trezor's email provider was breached, allowing attackers to send fake emails from genuine Trezor addresses. The fraudulent email, titled "Critical Security Alert: STM32 Entropy Vulnerability," falsely claims a hardware defect in Trezor devices. Trezor warns that wallet vendors never ask for sensitive information via email.

Published:

Updated:

What happened

Trezor, a company that makes hardware wallets for storing cryptocurrencies, reported that its third-party email provider was breached. Attackers sent phishing emails from real Trezor addresses. Trezor warned users not to click links and is still investigating.

Global impact / market context

This matters because phishing emails can trick users into revealing their recovery phrases, which are secret backup codes for wallets. If those are stolen, scammers can access and take cryptocurrency.

What to watch

  1. Trezor's investigation results: if they confirm how the breach happened, it could show whether user data was also exposed.
  2. Any further official warnings or updates from Trezor: this tells whether the threat is ongoing or resolved.
  3. Reports of users falling for the phishing scam: this shows how many people are affected and if the attack is spreading.

Evidence