LOOK CRYPTO · DATA PIPELINE

Data collection status

Checking collection status…

← All news
CRYPTO NEWS

Trezor and BitBox Warn Users About Fake Hardware Wallet Security Alerts

Cointelegraph · Ezra Reguerra

Hardware wallet manufacturers Trezor and BitBox have alerted users to phishing emails disguised as urgent security alerts following suspected breaches of third-party email service providers. The companies caution recipients against clicking any links in such messages to prevent possible asset compromise.

Phishing Attacks Via Compromised Email Providers

On Wednesday, Trezor announced that its email provider had been breached, resulting in fraudulent emails titled "Critical Security Alert: STM32 Entropy Vulnerability." The company emphasized that this message was fake and urged users not to click any links within.

BitBox also warned the same day about a phishing email impersonating the company. Their preliminary review suggested their newsletter provider had been compromised, noting several Bitcoin companies using the same provider appeared targeted by similar attacks.

Recent Security Incidents in the Hardware Wallet Sector

Earlier on August 13, a breach at Trezor's shipping partner ShipMonk exposed data belonging to nearly 14,000 customers. On September 4, Trezor disclosed another data leak impacting 67,000 US customers.

In July, BitBox stated their devices were unaffected by a Coldcard random number generation vulnerability. In August, they released firmware updates fixing two critical vulnerabilities, with no reports of exploits or stolen funds so far.

Cointelegraph reached out to both Trezor and BitBox for comments but did not receive replies before publication.

Why it matters

The warnings issued by Trezor and BitBox about phishing emails stemming from suspected breaches of their email service providers highlight critical security risks for hardware wallet users. These incidents demonstrate that even leading companies in the crypto industry are vulnerable to attacks exploiting third-party service providers, which poses risks of asset compromise. Past data breaches and identified vulnerabilities further underline the need for constant vigilance and robust measures to protect user privacy and the security of digital asset storage.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗