Trezor, BitBox warn users after phishing emails target wallet holders

3 hours ago 2



Hardware wallet makers Trezor and BitBox have warned users about phishing emails disguised as urgent security notices after suspected compromises involving third party email services. Summary Trezor warned users not to click links in a fraudulent email claiming an STM32 entropy vulnerability after its email provider was breached. BitBox said its newsletter provider was likely compromised, with several Bitcoin companies appearing to have been targeted through the same provider. The phishing warnings follow recent hardware wallet security incidents, including a ShipMonk breach that exposed data belonging to more than 80,000 Trezor customers. BitBox patched two severe firmware vulnerabilities in August but reported no known exploitation or stolen user funds. Trezor said on Wednesday that its email provider had been breached and warned users not to interact with a fraudulent message titled “Critical Security Alert: STM32 Entropy Vulnerability.” The company told recipients not to click any links in the email. Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phi...

Read Entire Article