Fake Security Emails Hit Trezor and BitBox Users
Hardware wallet makers Trezor and BitBox are warning users about phishing emails disguised as urgent security notices. The messages, which appear to be from legitimate sources, urge recipients not to click on links or take any action.
Trezor confirmed that its email provider had been breached, specifically mentioning a message titled 'Critical Security Alert: STM32 Entropy Vulnerability' as fraudulent. The company advised users to disregard the email and not interact with it in any way.
BitBox also issued a warning about a phishing email claiming to be from the company itself. Preliminary investigations suggested that the newsletter provider for multiple Bitcoin companies, including BitBox, may have been compromised. This would explain why several firms appear to have received similar phishing messages.