According to ShibDaily, Trezor, a provider of hardware crypto wallets, has issued an urgent warning after attackers exploited its support contact form to send phishing emails to users. These emails, which requested wallet backups, were designed to mimic legitimate responses from Trezor's support team. The company emphasized that these emails are fraudulent and reminded users never to share their wallet backups, which should remain private and offline. Trezor assured that it would never request such sensitive information from its users.
The company clarified that the incident did not involve a breach of its email system. Instead, attackers used victims' email addresses to submit support requests, triggering automated replies that appeared to originate from Trezor's official support team. Trezor confirmed that the issue has been addressed and contained, and it is actively researching methods to prevent future abuse. The company urged users to stay vigilant and reiterated the importance of keeping wallet backups secure.
This incident is part of a broader wave of phishing attacks targeting key players in the cryptocurrency industry. Recently, CoinMarketCap removed a deceptive pop-up from its website that prompted users to verify their crypto wallets. The platform is conducting an internal investigation to determine the source and scope of the incident. Users on X raised concerns about the suspicious pop-up, identifying it as a phishing attempt. Such tactics, which involve impersonating reputable platforms to extract private keys or sensitive wallet data, are becoming increasingly common.
Scammers often use fake or hijacked accounts to distribute credible-looking links, posing a significant threat to users who may unknowingly compromise their assets. This incident serves as a reminder for crypto users to double-check sources and avoid clicking unsolicited links. As phishing tactics evolve, remaining cautious online is crucial. While platforms are expected to enhance their security measures, individual vigilance remains one of the strongest defenses against increasingly sophisticated digital threats.