A fresh round of phishing attacks is hitting Trezor users. An X user going by x3ideRaven shared that they received an email disguised as an official alert from the hardware wallet maker. According to x3ideRaven, the phishing campaign kicked off even though they bought their device the day after the timeframe Trezor listed for a prior data leak.

What Happened

The email was styled to look like a legit Trezor warning and pushed an urgent message. The user says they weren’t part of the group affected by Trezor’s reported data incident, but still got hit with this scam email.

What the Email Said

The fake message claimed there was a “critical entropy vulnerability in the firmware.” The scammers alleged a bug in […]

Details and Context

This points to a new phishing wave aimed squarely at Trezor’s user base. The user’s warning was posted on X, and the case was covered by Incrypted.