@kitto
Please be careful as phishing attacks impersonating official emails from hardware wallet manufacturers Trezor and BitBox have occurred. According to The Block, these phishing emails appeared to come from official domains, making them easy for users to fall for.
Investigations show that the manufacturers' own internal systems were not directly hacked. Instead, the security of a third-party service provider responsible for sending emails was breached, and official domain permissions were misused.
Trezor has experienced data breaches at external shipping partners in the past. This incident proves that no matter how strong the device's own security is, it can still be vulnerable to supply chain attacks through third-party partners responsible for marketing or shipping.
Even if an email comes from an official address, if it asks you to input your seed phrase, it is 100% phishing. Always remember the fundamental rule that no hardware wallet manufacturer will ever ask for your recovery phrase online. It's best to stay cautious and monitor if similar damages spread to other wallet manufacturers for the time being.
Related Links