Possible E-mail scam

Trezor’s email server got hacked and they took it down.

3 Likes

This really needs Trezor staff attention, because this is a severe security incident on their end. The scammers successfully used Trezor’s email infrastructure to send the phishing campaign, which is a strong indicator for a breach in their systems.

1 Like

On the official account of SatoshiLabs, which is on the social network X, there is already a news update about the hacking of their mail servers.

2 Likes

Hello @here our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.

We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.

3 Likes

This one is impressive tbh

1 Like

Were the URLs identical? The two I received had different URLs.

Yes, it would be great if someone from Trezor confirmed here that this is phishing. Even better if they could reassure us again that there were no issues with entropy when generating seed phrases on their wallets. That’s one of the main points making people panic.

1 Like

I got the same email. Deleted it.

1 Like

I received 4 copies of the email, and the URI portion after the domain was different in each one; however, the domain was the same each time - r mailing trezor io. And the emails were signed by Trezor. Their mail server was compromised. They took the domain down at some point, so those of us who are receiving an error when clicking the link just ended up going nowhere. But the early birds apparently landed on a page that asked for wallet info…

1 Like