Trezor warns users of email provider breach, phishing attacks
Trezor said the fake alert is tied to a breached email provider and warned users not to click links in the message.
- On Wednesday, Trezor and BitBox warned users of a phishing campaign after their shared third-party email provider was breached, with fraudulent messages falsely claiming a "Critical Security Alert: STM32 Entropy Vulnerability" to solicit wallet recovery phrases.
- Preliminary investigations suggest the companies' shared newsletter provider was compromised, enabling attackers to target multiple Bitcoin businesses simultaneously through the same infrastructure both Trezor and BitBox relied on.
- The phishing emails warned of "insufficient randomness" and "critically low 40-bit entropy" affecting devices, directing recipients to malicious domains requesting 12, 20, or 24 word recovery phrases under false pretense of verification.
- Both companies took down the malicious domains and instructed users not to click links or share wallet backups, though the compromised email provider allowed messages to bypass standard authentication protections.
- This follows a Coldcard firmware vulnerability disclosed in July involving weak random number generation that enabled attackers to steal approximately $38 million in Bitcoin, and Trezor's recent disclosure that 80,000 customers were affected by a separate ShipMonk breach.
34 Articles
34 Articles
Trezor, BitBox Warn Users as Phishing Emails Target Hardware Wallet Customers
Trezor and BitBox issued fresh phishing warnings after customers received fraudulent emails that appeared to originate from the hardware wallet companies’ communication channels. Both companies told users to avoid unexpected security messages, especially those that direct recipients to external links.Visit Website
Trezor, BitBox warn users after phishing emails target wallet holders
Hardware wallet makers Trezor and BitBox have warned users about phishing emails disguised as urgent security notices after suspected compromises involving third party email services. Trezor said on Wednesday that its email provider had been breached and warned users not…
Trezor warns users of email provider breach, phishing attacks
Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. [...]
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium














