Hardware Wallet Makers Warn of Phishing Emails Impersonating Them
Hardware wallet makers Trezor and BitBox have issued warnings to users about phishing emails that impersonate them. The emails, which claim to be urgent security notices, ask recipients to click on links or take other actions that could compromise their accounts. Trezor's email provider was breached, and the company warned users not to interact with a fraudulent message claiming an STM32 entropy vulnerability. BitBox said its newsletter provider was likely compromised after several Bitcoin companies were targeted through the same service.
Trezor's warning follows a recent customer data breach involving ShipMonk, which exposed data belonging to more than 80,000 users. The company emphasized that its own systems were not breached and that user wallets and recovery phrases remained secure. BitBox patched two firmware vulnerabilities in August but reported no known exploitation or stolen user funds.
The phishing campaign has taken several forms, including physical letters impersonating wallet manufacturers and directing recipients to scan QR codes for supposed authentication or transaction checks. Trezor and Ledger warned users that legitimate hardware wallet providers do not ask users to enter, scan, upload, or share recovery phrases through websites or other external channels.