Back Tradingview Trezor, BitBox warn users about fake hardware wallet security alerts
Hardware wallet makers Trezor and BitBox warned users phishing emails disguised as urgent security notices after suspected compromises involving third-party email services.
On Wednesday, Trezor said its email provider had been breached and warned that a message titled “Critical Security Alert: STM32 Entropy Vulnerability” was fraudulent. The company urged recipients not to click any links.
On the same day, Bitbox warned users a phishing email pretending to come from the company. The company said its preliminary review indicated that its provider was likely compromised, adding that multiple Bitcoin companies appeared to have been targeted through a shared provider.
The warnings come after several recent security disclosures across the hardware-wallet sector. On Aug. 13, a breach at Trezor shipping provider ShipMonk exposed data belonging to nearly 14,000 customers. On Sept. 4, Trezor disclosed that another 67,000 US customers were affected.
In July, BitBox said its devices were unaffected by a vulnerability involving Coldcard’s random-number generation. In August, it released an update fixing two severe firmware vulnerabilities, with no known exploitation or stolen funds reported.
Cointelegraph reached out to Trezor and BitBox for more information but did not receive responses before publication.
More news from Cointelegraph
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
