Hardware wallet maker Trezor disclosed that a third-party provider was breached, allowing scammers to send phishing emails titled « Critical Security Alert: STM32 Entropy Vulnerability ». The fake message claimed a serious security flaw was found in STM32 microcontrollers used in its devices, potentially affecting 25% of devices. Trezor said it took down the fraudulent domain and is investigating how hackers accessed its legitimate domain. This phishing campaign may also affect users of other brands such as BitBox. A previous incident involving logistics partner ShipMonk had exposed data from approximately 80,689 customers, including contact and delivery information.
Source: Read the original article

