Trezor owners have been targeted with fake data breach emails, according to Twitter post.
Mailchimp have confirmed that their service has been compromised by an insider in order to send malicious links to cryptocurrency firms.
Users subscribed to newsletters powered by Mailchimp received a slew of fake notifications. Fraudsters, who were impersonating the Trezor team, warned that the cryptocurrency holdings of their potential victims could be stolen due to a massive security breach.
The bogus domain name featured Punycode characters, which made it possible for the hackers to add a veneer of legitimacy to the fake app.
According to Bleeping Computer, the scammers created a fraudulent version of Trezor Suite that is almost indistinguishable from the real one on the surface. To make potential victims drop their guard, the app even included a legitimate-looking warning, which urged users not to enter their recovery seed in the wake of the recent phishing attacks (unless the physical device instructs them to do so).
Trezor Customers Targetted