Trezor, BitBox warn users about fake hardware wallet security alerts
Hardware-wallet makers Trezor and BitBox alerted users to phishing emails posing as urgent security notices after suspected breaches at third-party email services. Trezor said its email provider was compromised and flagged a fake message titled “Critical Security Alert: STM32 Entropy Vulnerability,” while BitBox warned a newsletter-sourced phishing attempt may stem from a shared provider breach.

Why It Matters
Users of cryptocurrency hardware wallets rely on trusted communications for security updates; attackers leveraging compromised mailing services can trick recipients into clicking malicious links and increase risk following recent data exposures in the sector.
Key Facts
- Companies issuing warnings: Trezor and BitBox
- Fraudulent message title flagged by Trezor: "Critical Security Alert: STM32 Entropy Vulnerability"
- Trezor statement: Said its email provider had been breached and warned recipients not to click links in the fake message (issued on Wednesday).
- BitBox preliminary finding: Indicated its newsletter provider was likely compromised and that multiple Bitcoin companies appeared targeted through a shared provider.
- ShipMonk breach (Aug. 13): Exposed data belonging to nearly 14,000 customers.
Hardware-wallet manufacturers Trezor and BitBox warned customers about phishing emails disguised as urgent security notices after apparent compromises of third-party mailing services. Both companies urged caution and indicated the messages were not legitimate communications from their teams. Trezor said on Wednesday that its email provider had been breached and identified a fraudulent alert titled "Critical Security Alert: STM32 Entropy Vulnerability." The company cautioned recipients against clicking any links in that message. No further technical details or remediation steps were provided in the initial notice. BitBox issued a separate warning after users received a phishing email purporting to come from the company. In a preliminary review, BitBox said its newsletter provider was likely compromised and suggested that several Bitcoin-related firms may have been targeted through the same service, though it did not list other affected companies. The alerts follow a string of security disclosures affecting the hardware-wallet ecosystem. On Aug. 13, a breach at shipping provider ShipMonk exposed data for nearly 14,000 customers, and on Sept. 4 Trezor reported that an additional 67,000 U.S. customers were impacted. BitBox has previously said its devices were not affected by a Coldcard random-number generation vulnerability in July and released an August firmware update addressing two severe bugs; the company reported no known exploitation or stolen funds. Cointelegraph contacted both Trezor and BitBox for more information but had not received responses before publication. Users are being advised to verify any unexpected security notices directly with device makers through official channels and avoid following links in unsolicited emails.
Keep Reading

US sanctions Xinbi scam marketplace, restrains $52M in crypto

Consensys Software Inc. Splits In Two, Rebrands As MetaMask
Hunter Biden's LAPTOP Falls 99% In Three Hours To TRUMP's Valuation
Arbitrum Watchdog Seeks Permanent Bans For Three Grant Recipients
Original source: Cointelegraph