Cryptocurrency hardware wallet maker Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks.

Affected customers received fake "critical security alert" emails from help@trezor.io claiming that a "hardware microcontroller vulnerability" in the STM32 microcontrollers used by Trezor cold storage wallets could expose their seeds to brute-force cracking.

The company said that it's investigating the breach and that the domain has been taken down to stop the attacks.

"Our third-party e-mail provider has been breached. Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link," Trezor warned.

"We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain."