Trezor, BitBox warn users about fake hardware wallet security alerts

MGBX Editorial Team4

BitBox said multiple Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor confirmed a breach at its em

This article is for informational purposes only and does not constitute investment advice. Digital asset markets are volatile; manage risk carefully.
Trezor, BitBox warn users about fake hardware wallet security alerts - BTC

Details

BitBox said multiple Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor confirmed a breach at its email service.

Hardware wallet makers Trezor and BitBox warned users about phishing emails disguised as urgent security notices after suspected compromises involving third-party email services.

On Wednesday, Trezor said its email provider had been breached and warned that a message titled “Critical Security Alert: STM32 Entropy Vulnerability” was fraudulent. The company urged recipients not to click any links.

On the same day, Bitbox warned users about a phishing email pretending to come from the company. The company said its preliminary review indicated that its newsletter provider was likely compromised, adding that multiple Bitcoin companies appeared to have been targeted through a shared provider.

The warnings come after several recent security disclosures across the hardware-wallet sector. On Aug. 13, a breach at Trezor shipping provider ShipMonk exposed data belonging to nearly 14,000 customers. On Sept. 4, Trezor disclosed that another 67,000 US customers were affected .

In July, BitBox said its devices were unaffected by a vulnerability involving Coldcard’s random-number generation. In August, it released an update fixing two severe firmware vulnerabilities, with no known exploitation or stolen funds reported.

Cointelegraph reached out to Trezor and BitBox for more information but did not receive responses before publication.

Related: Cronos confirms $9.2M slipped away before Tectonic exploit rollback

Subscribe to daily byte-sized crypto news from Cointelegraph

Uzbekistan begins government bond-backed stablecoin payment pilot

Cronos confirms $9.2M slipped away before Tectonic exploit rollback

Harmony proposes shutting down layer 1, migrating ONE to Ethereum

Uzbekistan begins government bond-backed stablecoin payment pilot

Cronos confirms $9.2M slipped away before Tectonic exploit rollback

Harmony proposes shutting down layer 1, migrating ONE to Ethereum

US sanctions Xinbi scam marketplace, restrains $52M in crypto

Bitcoin fails to reclaim $80K as Bessent fuels yen strength around 153 per dollar

Metaplanet’s executive stock pool sparks shareholder backlash as CEO addresses MMXX ties

Trezor, BitBox warn users about fake hardware wallet security alerts

Cointelegraph is committed to providing independent, high-quality journalism across the crypto, blockchain, AI, and fintech industries.

All news, reviews, and analyses are produced with full journalistic independence and integrity. For more details on our standards and processes, please read our Editorial Policy .

BTC

Source

Cointelegraph RSS

Source: Cointelegraph RSS