The link, when tapped, downloads an app that asks the victim for their wallet backup password. According to Trezor, one of the email subject lines said: “Critical Security Alert: STM32 Entropy Vulnerability.”
With a stolen wallet password, a hacker can irreversibly steal the person’s funds on the public blockchain.
The breach highlights a common security incident, where hackers compromise data held by third-party companies that are necessary for fulfilling orders or purchases from customers. Trezor says none of its products, wallets, or account system was affected by the incident.
This is the second breach in recent weeks affecting Trezor, after the company alerted customers in August that one of its shipping partners was . The incident at the mailing company ShipMonk exposed the names, phone numbers, email addresses, and postal addresses of who bought and received Trezor wallet hardware.
The data breach could put crypto owners and other wealthy individuals at risk of , which rely on physical attacks to extract passwords from people.
In the weeks following the breach at ShipMonk, some people have received letters by mail claiming to be from Trezor, featuring a QR code that, when scanned, opens up a fake page that attempts to steal the victim’s crypto wallet password.
Trezor said it was reevaluating its relationships with its vendors and warned customers that their email addresses may be used again for future phishing attacks.
