Trezor's official domain got compromised. Hackers gained access through a third-party email provider and used it to send out phishing emails, pretending to be from Trezor, with fake warnings about a “critical vulnerability.” Trezor has already taken the domain offline and launched an investigation. If you get one of these emails, ignore it and don’t click any links.
How the Attack Went Down
The whole scam played on trust in the Trezor brand: emails came from the hacked domain and looked like urgent security alerts. The goal was to get users to click the links inside. Clicking any of those puts your devices and funds at serious risk.
What Trezor Says
The company announced it has taken the domain offline and is investigating the breach. No further details about the incident are public as of now.
How to Stay Safe
• Don’t click links or download files from sketchy emails, even if they look “official.”
• Only access the Trezor site by typing the address yourself or using your own bookmarks.
• Double-check domain names and sender addresses; if something seems off, verify info through Trezor’s official channels.
• Never enter your seed phrase or private keys on websites or in email replies.
Background
Trezor has had a data leak in the past.
