WRITTEN IN PLAIN AMERICAN ENGLISH.
About
CLAY TRIBUNE.
ShopCartAccount
Advertisement

Trezor and BitBox Warn Users of Fake Security Alert Phishing Emails

Trezor and BitBox warn users of phishing emails posing as security alerts after third-party email provider breaches, urging caution.

By mitch·7 min read
A hardware wallet on a desk with a glowing red warning envelope icon above it.

Hardware wallet makers Trezor and BitBox warned users about phishing emails disguised as urgent security notices after suspected compromises involving third-party email services. Both companies issued alerts on the same day, telling customers to treat unsolicited security messages with suspicion.

On Wednesday, Trezor said its email provider had been breached and warned that a message titled “Critical Security Alert: STM32 Entropy Vulnerability” was fraudulent. The company urged recipients not to click any links.

On the same day, BitBox warned users about a phishing email pretending to come from the company. BitBox said its preliminary review indicated that its newsletter provider was likely compromised, adding that multiple Bitcoin companies appeared to have been targeted through a shared provider.

Advertisement

The warnings come after several recent security disclosures across the hardware-wallet sector, and they highlight a persistent weakness: the third-party services that connect device makers to their customers.

Trezor’s Email Provider Breach

Trezor confirmed that its email service had been breached, allowing fraudulent messages to be sent to its customer base. The company identified the fake email by its subject line, “Critical Security Alert: STM32 Entropy Vulnerability,” and moved quickly to alert users that the message did not come from legitimate Trezor channels.

The phishing email was crafted to appear as an urgent security warning, a common tactic designed to push recipients into clicking malicious links without thinking. Trezor’s warning was direct: do not click any links in the message.

The company did not provide details on how the breach occurred or how many customers may have received the fake email.

BitBox Reports Shared Provider Compromise

BitBox issued its own warning on the same day, telling users about a phishing email that pretended to come from the company. The hardware wallet maker said its preliminary review indicated that its newsletter provider was likely compromised.

“Its preliminary review indicated that its newsletter provider was likely compromised.”

The company went further, noting that multiple Bitcoin companies appeared to have been targeted through a shared provider. That detail suggests the attack was not aimed at BitBox alone but was part of a broader campaign against several firms in the Bitcoin space.

BitBox did not name the newsletter provider or the other companies it believed were targeted. The company’s warning urged users to be cautious about emails claiming to be from BitBox.

Trezor’s Recent Security Disclosures

The email breach is not the first security problem Trezor has faced this year.

On Aug. 13, a breach at Trezor’s shipping provider ShipMonk exposed data belonging to nearly 14,000 customers. That incident involved the shipping company, not Trezor’s own systems, but it still put customer information at risk.

On Sept. 4, Trezor disclosed that another 67,000 US customers were affected. The two disclosures together represent a significant exposure of customer data.

BitBox’s Security Record

BitBox has faced a number of security issues this year. In July, the company said its devices were unaffected by a vulnerability involving Coldcard’s random-number generation. That vulnerability affected a competing hardware wallet maker, and BitBox was quick to confirm that its own products were not impacted.

In August, BitBox released an update fixing two severe firmware vulnerabilities. The company said there was no known exploitation of those vulnerabilities and no stolen funds were reported.

The firmware update and the July statement show a company that has been attentive to security issues, even when they do not directly affect its products. The phishing warning this week, however, points to a vulnerability that sits outside the hardware itself: the third-party services that companies rely on to communicate with their customers.

The Phishing Pattern

The phishing emails sent to Trezor and BitBox customers follow a familiar pattern. A third-party email service is compromised, and that access is then used to send messages that look like they come from a trusted company. The messages are designed to create a sense of urgency, pushing recipients to act before they have time to think.

In Trezor’s case, the fake email was titled “Critical Security Alert: STM32 Entropy Vulnerability.” The title references a real technical concept — entropy is a measure of randomness. By using that language, the email looked plausible to users who follow security news.

The BitBox phishing email followed a similar approach, pretending to be an official communication from the company. BitBox’s warning suggests the same compromised provider may have been used to target multiple companies at once.

What Users Should Do

Both companies have been clear about what users should do if they receive a suspicious email. Do not click any links.

For Trezor users, the company specifically identified the fraudulent email by its subject line, “Critical Security Alert: STM32 Entropy Vulnerability.” Any message with that title should be treated as a phishing attempt.

For BitBox users, the warning is broader: be cautious about any email that claims to come from the company. Users should verify any security alert through official channels — the company’s website, its support team, or its verified social media accounts — rather than trusting an email that arrives unsolicited.

Hardware Wallets and Third-Party Risk

Hardware wallets are designed to keep cryptocurrency private keys offline, away from internet-connected devices that could be compromised. But the devices themselves are only part of the security picture.

The companies that make these devices rely on a web of third-party services — email providers, newsletter platforms, shipping companies — to run their businesses. Each of those services is a potential point of failure. A breach at a shipping provider can expose customer data. A compromise at an email provider can enable phishing attacks. The hardware itself may be secure, but the ecosystem around it has vulnerabilities.

This week’s warnings are a reminder that security is not just about the device in your hand. It is also about the systems that connect the device maker to its customers. When those systems fail, the consequences can be serious, even if no funds are lost directly.

Unanswered Questions

Cointelegraph reached out to Trezor and BitBox for more information about the phishing attacks but did not receive responses before publication. The companies have not yet provided additional details about the scope of the email breach or the suspected compromise at the shared newsletter provider.

It is not known how many customers received the phishing emails or whether any users fell victim to the attacks. Neither company has reported stolen funds in connection with the phishing campaign, but the full impact may not be clear for some time.

The lack of immediate response from either company is not unusual. Security incidents take time to investigate, and companies are often cautious about sharing details before they have a full picture of what happened.

Related Incidents in the Sector

The phishing warnings come after several recent security disclosures across the hardware-wallet sector. Trezor’s shipping provider breach exposed data belonging to nearly 14,000 customers on Aug. 13, followed by a Sept. 4 disclosure that another 67,000 US customers were affected.

In the broader cryptocurrency space, security incidents continue to be a concern. A separate incident involving the Tectonic exploit saw $9.2M slip away before a rollback could be executed, according to Cronos. That incident appears to be unrelated to the hardware wallet phishing campaign but underscores the persistent threats facing the crypto ecosystem.

For hardware wallet users, the advice remains the same: treat unsolicited security alerts with suspicion. The devices themselves are built to protect your keys. The emails in your inbox are another matter entirely.

The Bottom Line

Trezor and BitBox have both issued warnings about phishing emails. The shared provider angle that BitBox mentioned suggests the attack may have been broader than two companies.

For now, users should stay vigilant. If an email claims to be a security alert from a hardware wallet company, verify it through official channels before taking any action. The phishing emails are designed to look real, but they are not.

The hardware wallet sector has weathered security incidents before, and it will weather this one. But each incident is a reminder that the ecosystem around these devices is only as strong as its weakest link. This week, that weak link was email.

Source: cointelegraph.com

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.