🚨Trezor Users Targeted by Terrifying Phishing Attack After Third-Party Breach
$VTHO
In January 2024, attackers breached a third-party support portal used by Trezor, exposing the names and emails of up to 66,000 customers who'd contacted support since December 2021. No funds or seed phrases were compromised in the breach itself, but at least 41 users received direct phishing emails from the attacker requesting sensitive recovery-seed info. Days later, a spoofed "noreply@trezor.io" email pushed a fake "network upgrade" scam designed to steal seed phrases — Trezor managed to kill the malicious link before major damage. Similar phishing waves have recurred since (2022, 2023, and again over a year later via Trezor's own contact form). The consistent takeaway: the device wasn't hacked, but Trezor's support/communication channels have repeatedly been abused to trick users into giving up their recovery seed — the one thing that should never be entered online.
$VTHO
In January 2024, attackers breached a third-party support portal used by Trezor, exposing the names and emails of up to 66,000 customers who'd contacted support since December 2021. No funds or seed phrases were compromised in the breach itself, but at least 41 users received direct phishing emails from the attacker requesting sensitive recovery-seed info. Days later, a spoofed "noreply@trezor.io" email pushed a fake "network upgrade" scam designed to steal seed phrases — Trezor managed to kill the malicious link before major damage. Similar phishing waves have recurred since (2022, 2023, and again over a year later via Trezor's own contact form). The consistent takeaway: the device wasn't hacked, but Trezor's support/communication channels have repeatedly been abused to trick users into giving up their recovery seed — the one thing that should never be entered online.
