Phishing emails sent to Trezor and BitBox users falsely warned of critical security flaws and attempted to lure recipients into clicking malicious links.

Hardware wallet maker Trezor said a fake security alert claimed a hardware flaw could expose users’ recovery phrases.

This follows last month's security breach at shipping provider ShipMonk, which exposed the personal information of Trezor customers.

Attackers exploit legitimate mailing channels to demand crypto wallet backups