Trezor and BitBox Users Targeted by Phishing Scam Following Email Provider Breaches
Hardware wallet makers warn of phishing emails
Hardware wallet manufacturers Trezor and BitBox have warned their users about a phishing campaign impersonating their brands. A hardware wallet is a physical device that stores the security keys for cryptocurrency offline to keep them safe from hackers.
The attackers sent emails designed to trick people into giving away their private information by claiming there was a critical security flaw. Both companies have urged users not to click any links or follow instructions contained in these messages.
Key facts about the phishing attempt
- The phishing emails used the subject line "Critical Security Alert: STM32 Entropy Vulnerability."
- Trezor confirmed that its third-party email provider was breached.
- BitBox stated it is likely that its newsletter provider was compromised.
- The "STM32" alert is fake and was used as a way to scare users into acting.
Official statements from Trezor and BitBox
Trezor identified the phishing attempt on September 9 and successfully took down the domain used by the attackers. On September 10, the company reassured its customers that their hardware wallets remain safe. However, the company noted that the safety of funds depends on users keeping their recovery seeds private. A recovery seed is a list of words used to back up and restore access to a crypto wallet.
BitBox also issued a warning on September 9. Their preliminary investigation suggests that other Bitcoin companies may be affected because they appear to share the same compromised newsletter provider. BitBox has reported the phishing domains and warned all of its newsletter subscribers about the incident.
Confirmed details and risks
It is confirmed that the attackers gained access to legitimate communication channels used by Trezor and BitBox through third-party services. It is also confirmed that the physical hardware wallets themselves have not been hacked. The risk lies entirely in "social engineering," where attackers try to trick users into revealing their recovery words.
Why this matters for crypto holders
This event shows that even if a hardware wallet is secure, users can still lose their money if they are tricked by fake messages. Trezor and BitBox emphasize that anyone who obtains a recovery seed can move the funds associated with that wallet. This highlights the importance of never sharing recovery words with anyone and only downloading wallet software from official websites.
Next steps for users
BitBox is continuing its investigation into the breach. Users are advised to ignore any suspicious emails and check only the official company channels for security updates. Most known phishing links associated with this attack have already been taken down.