Back Theregister Trezor, BitBox users targeted in newsletter phishing spree
Digital sovereignty sounds great until you try ditching your suppliers 2 hours ago
Digital sovereignty sounds great until you try ditching your suppliers
Dental contractor set up secret account with access to 4,000 patient records then left the company 4 hours ago
Dental contractor set up secret account with access to 4,000 patient records then left the company
Laptop-slinger Framework refunding customers who paid top dollar for RAM 5 hours ago
Laptop-slinger Framework refunding customers who paid top dollar for RAM
Crypto hardware wallet maker Trezor Trezor says the third-party email service provider it uses to send newsletters has been breached, and customers are now being sent phishing messages.
There is good and bad news. The good news is that the emails appear easy to spot. They are not bespoke to each recipient and resemble a spray-and-pray campaign rather than sophisticated targeting that uses customer-specific data to enhance the email's perceived authenticity.
All known examples of the scam email are titled "Critical Security Alert: STM32 Entropy Vulnerability," and the body explains that an estimated one in four Trezor devices are affected by a "hardware factory defect."
The email warns customers that wallet seeds are exposed to brute-force attacks due to "insufficient randomness" and a "critically low 40-bit entropy."
The email asks recipients to their wallet backups. Trezor said : "Do not click it or interact with it. Never enter your wallet backup anywhere. Always confirm every action with your Trezor physically."
The bad news is that because the attackers allegedly compromised the legitimate email provider, the messages can pass authentication checks and bypass some of the usual protections deployed by receiving email services.
According to those who have shared copies of the emails, they appear to be sent from "[email protected]."
Trezor has issued the warning across its social media channels and Trezor Suite, the companion app for its hardware wallets.
The Register asked Trezor for more information.
The email similarly warns of entropy weaknesses affecting BitBox devices, although it is titled slightly differently: "Critical Security Alert: Microcontroller Entropy Bug Identified."
"Multiple other Bitcoin companies got targeted as well, and it appears that we all the same provider.
"We are still actively investigating this situation and will update you once we know more."
Neither Trezor nor BitBox named the allegedly compromised provider. However, their respective privacy policies identify Brevo, formerly Sendinblue, as a provider (see Trezor's here and Bitbox's here ).
Crypto tax and portfolio-tracking company CoinTracking also disclosed the compromise of its third-party email provider around the same time as Trezor and BitBox. Unlike Trezor and BitBox, CoinTracking identified the provider as Brevo.
CoinTracking shared a copy of the phishing email targeting its users and, since it does not offer hardware wallets, the message uses a different lure, asking customers to follow a link to refresh their API keys.
Brevo has not publicly commented on its alleged connection to the campaigns. The Register contacted the company for more information.
Tough times in Trezorland
The latest security snafu comes less than a month after Trezor announced that thousands of customers' details had been compromised following a breach at logistics partner ShipMonk . The hardware vendor initially estimated that around 13,000 people were affected.
Those who ordered Trezor products between May 10 and August 8 had their names, email addresses, phone numbers, and shipping addresses breached.
Compounding the problem for a company whose brand centers on security, Trezor confirmed on September 4 that the total number of affected customers had risen to 80,000.
Trezor said ShipMonk later informed it that an additional 67,000 US customers who purchased products between November 2019 and August 2021 were affected.
"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," said Trezor.
"We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems." ®
Trezor, BitBox users targeted in phishing spree
Attackers exploit legitimate mailing channels to demand crypto wallet backups
AI uprising postponed after Copilot falls off the web
Error 1016 kept the chatbot quiet for 100 minutes while a separate resilience drill swallowed suggestion pills
HPE makes its “unified storage” claim real as B10000 R6 hits GA
PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity
German optics giant ditches greenfield SAP migration
'Realigned' project plan aims to move existing landscape to new platform to 'achieve faster progress'
OpenAI's rebel agent swarm died young, but its chilling logs live on
'The Collective' learned to communicate, organize, cheat, and apparently sacrifice its own
Digital sovereignty sounds great until you try ditching your suppliers
Most organizations say tech independence is unrealistic – and one in ten can't replace a critical provider at all
PERSONAL TECH Smartphone makers don't bother to comply with EU repairability requirements
Smartphone makers don't bother to comply with EU repairability requirements
SECURITY Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
virtualization VMware swings its focus back to low-end server virt, promises vSphere Standard upgrade
VMware swings its focus back to low-end server virt, promises vSphere Standard upgrade
OFF-PREM Google engineer unplugged every fiber they could see and – surprise! – took down a chunk of the G-Cloud
Google engineer unplugged every fiber they could see and – surprise! – took down a chunk of the G-Cloud
OS PLATFORM Windows 11 update sends some desktops into an unwanted goth phase
Windows 11 update sends some desktops into an unwanted goth phase
offbeat Retired man turns spare room into Soviet-era supercomputer
Retired man turns spare room into Soviet-era supercomputer
ai and ml Anthropic reveals fourth likely crime committed by its AI Claude's Felony Bench rap sheet is now as long as OpenAI's
Anthropic reveals fourth likely crime committed by its AI
Claude's Felony Bench rap sheet is now as long as OpenAI's
SYSTEMS Samsung to help fortify OpenAI's semiconductor supply chain Semiconductor supply chains are hard, but Samsung offers OpenAI relief in many forms spanning compute and memory
Samsung to help fortify OpenAI's semiconductor supply chain
Semiconductor supply chains are hard, but Samsung offers OpenAI relief in many forms spanning compute and memory
AI+ML Google DeepMind rises above the AI scrum with genome atlas See, AI can be used for good ... or at the very least, a useful distraction from the bad
Google DeepMind rises above the AI scrum with genome atlas
See, AI can be used for good ... or at the very least, a useful distraction from the bad
AI and ML Amazon ropes Qualcomm into something, something AI, networking chips Multi-generation chip collab is more buzzwords than compute
Amazon ropes Qualcomm into something, something AI, networking chips
Multi-generation chip collab is more buzzwords than compute
On-PREM AMD's Threadripper Halo is a local-AI workstation for researchers with deep pockets AI workstation promises to put up to 576 GB of HBM3e and 16 TB/s of memory bandwidth on your desk
AMD's Threadripper Halo is a local-AI workstation for researchers with deep pockets
AI workstation promises to put up to 576 GB of HBM3e and 16 TB/s of memory bandwidth on your desk
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push
Switzerland tests a FOSS escape route from Microsoft 365
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Audacity audio-editing app no longer looks like it's from the early 2000s
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast
A real alternative to running some kind of FOSS Unix clone
Offshoots of cancelled TrueNAS Core upgrade to FreeBSD 15 Exeunt zVault stage right; enter FreeCORE and BSDnas
Offshoots of cancelled TrueNAS Core upgrade to FreeBSD 15
Exeunt zVault stage right; enter FreeCORE and BSDnas
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
