Trezor Security Alert: Fake Emails Sent From Legitimate Address — Konteks untuk pasar | Labapro News
← Kembali ke News
Market Update

Trezor Security Alert: Fake Emails Sent From Legitimate Address — Konteks untuk pasar

## Trezor Security Alert: Fake Emails Sent From Legitimate Address — Konteks untuk pasar

### Fakta

Market News

Trezor’s wallets and private keys were not exposed, but attackers exploited a third-party email provider.

The fraud domain has been taken down, and investigators are looking into how attackers accessed a legitimate sending address.

Trezor has confirmed that a third-party email service provider it uses was breached, allowing attackers to send phishing emails directly from the firm’s own legitimate domain. The fraudulent email carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability,” designed to convince recipients that their hardware wallets were compromised and that immediate action was required.

Trezor has been clear: the email is fake. The incident compromised no wallets or private keys and led to the immediate shutdown of the domain. An investigation is underway into how attackers gained access to a legitimate Trezor sending address. It is the detail that makes this attack more dangerous than a typical fraud attempt. When a phishing email arrives from a real company domain, standard detection methods often fail.

Three Vendor Failures in Four Weeks

In August, shipping provider ShipMonk suffered a breach that exposed personal data belonging to 80,689 Trezor customers. It included names, email addresses, phone numbers, and home addresses. Trezor warned at the time that the leaked information could be used for more sophisticated follow-up attacks. That warning has now materialised.

Earlier, Trezor’s support portal exposed data for approximately 66,000 users. Trezor has not publicly linked these three incidents, but the sequence is. Significantly, the support portal breach, shipping partner breach, and email provider breach point to a focus on targeting Trezor’s peripheral infrastructure rather than the wallets themselves.

In addition, attackers go through the suppliers, the logistics partners, and the email providers. The parts of the chain that carry real access and real data but often operate with less review.

What Trezor Users Need to Do?

Do not click any links in unexpected Trezor emails, particularly anything referencing STM32 or entropy vulnerabilities. Never enter a recovery phrase or device passcode into any website reached through an email link. Treat unexpected phone calls or physical letters claiming to be from Trezor as hostile until verified independently.

For official communications, go directly to trezor.io or Trezor’s verified account on X. Anyone who entered a backup phrase on a linked site should move funds to a new wallet immediately.

Moreover, Trezor has kept three key details private: the name of the breached email provider, the number of customers receiving the fraudulent message, and whether anyone accessed customer data.

share

Sarayu Krishna

Content Writer | Crypto Enthusiast | Bridging Literature and Blockchain

### Konteks

Peristiwa ini terkait pasar.

### Potensi Dampak

Volatilitas jangka pendek dapat meningkat; arah tidak dapat dipastikan.

### Catatan Risiko

Konten ini bersifat informasi dan edukasi pasar, bukan ajakan atau jaminan keuntungan. Trading mengandung risiko; keputusan tetap pada masing-masing individu. Bukan nasihat finansial personal.

Siap ambil peluang market?

Install aplikasi Labapro dan mulai trading dari satu platform multi-asset.

Trading Sekarang
Bagikan artikel ini

Bantu trader lain membaca update market Labapro. Preview share memakai title, image, dan description artikel ini.