Trezor Addresses Phishing Incident, Assures No Breach of User Data
Hardware wallet manufacturer Trezor has confirmed a security incident involving its customer support system, where attackers exploited an auto-reply mechanism to send phishing emails. The company emphasized that no user data or email systems were compromised.
The fraudulent emails, disguised as legitimate Trezor communications, prompted users to share wallet backups—a request the company explicitly warns against. "Security is a continuous process," Trezor stated, urging vigilance.
The breach was contained after attackers submitted queries through Trezor's public contact form, triggering automated responses. The firm reiterated that wallet backups must remain private and offline.