Hardware wallet Trezor suffers security vulnerability at a third-party email service provider; users must be vigilant against phishing attacks
On September 10, according to PeckShieldAlert’s latest post, hardware wallet manufacturer Trezor today issued a security warning stating that its third-party email service provider has experienced a security vulnerability, putting users at risk of phishing attacks.
Blockchain security firm PeckShield monitoring found that a phishing email with the subject “Critical Security Alert: STM32 Entropy Vulnerability” is currently spreading. The email forges the sender address as help@trezor.io, which is not a legitimate communication from Trezor.
As indicated by the urgent statement shared on social media that it cites, Trezor’s official account clearly states that this email is a phishing attempt and reminds users not to click any links in it.
The company also said that it has taken swift action, removed the relevant domains, and is conducting an in-depth investigation into this security incident. It remains unclear how many users may have been affected and whether any users suffered losses as a result.
Security experts recommend that Trezor users stay highly vigilant. For emails claiming to be from the hardware wallet provider, be sure to verify through official channels and avoid directly clicking links in the email or downloading attachments to reduce the risk of having assets stolen.
#Trezor #钱包钓鱼攻击
On September 10, according to PeckShieldAlert’s latest post, hardware wallet manufacturer Trezor today issued a security warning stating that its third-party email service provider has experienced a security vulnerability, putting users at risk of phishing attacks.
Blockchain security firm PeckShield monitoring found that a phishing email with the subject “Critical Security Alert: STM32 Entropy Vulnerability” is currently spreading. The email forges the sender address as help@trezor.io, which is not a legitimate communication from Trezor.
As indicated by the urgent statement shared on social media that it cites, Trezor’s official account clearly states that this email is a phishing attempt and reminds users not to click any links in it.
The company also said that it has taken swift action, removed the relevant domains, and is conducting an in-depth investigation into this security incident. It remains unclear how many users may have been affected and whether any users suffered losses as a result.
Security experts recommend that Trezor users stay highly vigilant. For emails claiming to be from the hardware wallet provider, be sure to verify through official channels and avoid directly clicking links in the email or downloading attachments to reduce the risk of having assets stolen.
#Trezor #钱包钓鱼攻击

