Trezor says third-party breach enabled phishing from its official domain
Trezor said its third-party email provider was breached, enabling phishing emails to be sent from its official domain. It warned that a specific “Critical Security Alert: STM32 Entropy Vulnerability” email is not coming from it and is a phishing attempt.