Hardware wallet maker Trezor said its third-party email provider had been breached, enabling phishing emails to be sent from its official domain.
"Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link," Trezor wrote in an X post on Wednesday.
Trezor said it has since taken down the domain and is investigating the situation, including how the hackers were able to use its official domain for the phishing emails.
On the same day, BitBox, a Swiss bitcoin (BTC) hardware wallet maker, reported a similar phishing email circulating under its disguise.
Marcello Paz, a crypto commentator with X username "MHPaz," said he received the phishing email, sharing screenshots showing that it asked customers to update their hardware wallets due to a "critical" vulnerability that could affect newer devices. The email credentials show official domain names and signatures, unlike typical phishing emails that use similar but fake addresses.











