Marthio Marthio
TechnologyCrypto

Trezor and BitBox Warn Users About Phishing Emails Targeted via Compromised Newsletter Providers

Hardware wallet maker Trezor and provider BitBox issued alerts about fraudulent security emails linked to breached third-party services, following a wave of recent industry breaches.

Hardware wallet manufacturers Trezor and BitBox issued warnings regarding phishing campaigns masquerading as critical security notices. Trezor stated its email service provider was breached on Wednesday after users received messages referencing an alleged STM32 entropy vulnerability. The company advised recipients not to follow any embedded links. Simultaneously, BitBox warned that its newsletter provider appeared compromised, noting multiple Bitcoin companies targeted via this shared infrastructure. This incident follows other significant security failures in the sector, including a breach at Trezor's shipping partner ShipMonk in late August affecting nearly 14,000 customers and another disclosure earlier this month impacting 67,000 U.S. clients. Meanwhile, BitBox recently reported fixing two severe firmware vulnerabilities with no stolen funds or exploitations occurring. Both companies contacted journalists for further details before publication.

Hardware walletCybersecurityPhishingBitboxTrezorCrypto securityEmail breach