I am a new user and registered just recently, so Trezor’s forum does not let me post again to the topic “Possible E-mail scam”. Apologies for making noise, but I deem it’s important.
Please look up my posts there first.
The phishing mail would make you download an HTML file, which in turn would steal your seed phrase, posting it to a Telegram bot via its API (using the embedded Javascript in the HTML file).
The only remaining serious concern is the sending mailserver. I got 4 scam mails in the past 30-60 minutes all together and all of them was sent using Trezor’s seemingly own mail server:
Received: from mailing.trezor.io (mailing.trezor.io [172.246.19.223])
The DNS reverse and forward records match, I’ve checked.
The question is: how was this possible?
An official reply from Trezor is a must at this point.
Hello @here our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.