u.today
Phishing Attack Targets Trezor and BitBox Users via Compromised Email Provider
Article Content
A phishing campaign has targeted users of Trezor and BitBox hardware wallets following a breach of a third-party email provider. The attackers sent fraudulent emails titled 'Critical Security Alert: STM32 Entropy Vulnerability,' misleading users into believing their wallets were compromised. Trezor confirmed that the emails passed authentication checks, making them difficult to identify as phishing attempts. The emails urged users to share sensitive information, such as wallet recovery phrases. Trezor and BitBox have warned customers not to interact with these emails and are investigating the breach. CoinTracking, another crypto service, also reported similar phishing attempts. The breach has raised concerns about the security of third-party email services used by cryptocurrency companies. Trezor previously disclosed a separate data breach affecting over 80,000 customers in August 2026.
Key Points: • Phishing emails targeted Trezor and BitBox users, exploiting a third-party email provider breach. • Fraudulent emails passed authentication checks, complicating detection efforts. • Trezor and BitBox have advised users not to engage with the phishing attempts.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.