Trezor and BitBox Warn Users of Fake Security Alerts via Phishing Emails
Hardware wallet makers Trezor and BitBox have issued warnings to users about phishing emails disguised as urgent security notices. The messages are believed to be linked to breaches involving third-party email services.
Trezor's email provider was compromised, prompting the company to warn recipients not to click any links in a message titled 'Critical Security Alert: STM32 Entropy Vulnerability'. BitBox also issued a warning after discovering that its newsletter provider had been compromised. Multiple Bitcoin companies are thought to have been targeted through this shared provider.
These warnings come amid recent security disclosures within the hardware wallet sector. In August, nearly 14,000 Trezor customers were affected by a breach at shipping provider ShipMonk, while another 67,000 US customers were impacted in September.