X user under the pseudonym x3ideRaven reported receiving a phishing email disguised as a message from Trezor. According to him, he purchased a device the day after the company's reported data breach period, but still started receiving fraudulent messages.
The fake email claimed to be about a supposed "critical entropy vulnerability in the firmware." The attackers alleged that a bug in a 2021 update could affect seed phrase generation on some devices.
Specifically, the email claimed that due to a configuration error, vulnerable firmware versions could use a non-cryptographic pseudorandom number generator instead of a hardware true random number generator. Supposedly, this could reduce the seed phrase entropy from 128 to 40 bits.
Trezor stated that they are aware of the new wave of phishing.
"We have confirmed that attackers are using a combination of data from different database leaks at several cryptocurrency services. It is quite possible that some KYC data may have been compromised, and the attackers are now trying their luck," the company noted.
The team reminded about a previous security incident related to a third-party tool and mailing list subscriber email addresses. Company representatives suggested this case could be linked to the current phishing campaign.
Trezor also added that they have already taken measures to prevent further leaks.
Recall that approximately two weeks prior to this report, Trezor announced a leak of customer personal data due to a hack of their logistics partner ShipMonk. The incident affected 13,689 buyers.
end-content




