Hardware Wallet Makers Trezor and BitBox Issue Phishing Warnings
Trezor and BitBox, two prominent hardware wallet manufacturers, have issued warnings to their users about fake security alerts. The companies believe that hackers are using phishing emails disguised as urgent security notices after suspected compromises involving third-party email services.
Trezor stated that its email provider had been breached and warned users not to click on a message titled 'Critical Security Alert: STM32 Entropy Vulnerability', which was deemed fraudulent. The company's preliminary review suggested that the message was part of a phishing campaign targeting multiple Bitcoin companies through a shared provider.
This warning comes after recent security disclosures within the hardware wallet sector, including a breach at Trezor's shipping provider ShipMonk in August, which exposed data belonging to nearly 14,000 customers. Additionally, on September 4, Trezor disclosed that another 67,000 US customers were affected.
CoinTelegraph reached out to both companies for further information but did not receive responses before publication.