Trezor and BitBox Issue Warnings Over Fake Security Alerts
Hardware wallet makers Trezor and BitBox have issued warnings to their users about fake security alerts. The emails, designed to look like urgent notices from the companies, were sent out after a breach at an email provider shared by several Bitcoin businesses.
Trezor's email provider was compromised, leading to a message titled 'Critical Security Alert: STM32 Entropy Vulnerability' being sent out. The company urged recipients not to click on any links in the email, as it was fraudulent.
BitBox also warned its users about a phishing email pretending to come from the company, stating that its preliminary review indicated its newsletter provider was likely compromised. Several Bitcoin companies appeared to have been targeted through a shared provider.
This comes after recent security disclosures in the hardware-wallet sector. A breach at Trezor's shipping provider ShipMonk exposed data belonging to nearly 14,000 customers on Aug. 13. Another 67,000 US customers were affected on Sept. 4.