Fake Security Emails Target Trezor and Bit
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Hardware wallet manufacturers Trezor and BitBox alerted users to phishing emails masquerading as urgent security warnings. Trezor stated its email provider was breached, with a fraudulent message titled “Critical Security Alert: STM32 Entropy Vulnerability” circulating. BitBox's preliminary review suggested its newsletter provider was compromised, affecting multiple Bitcoin companies through a shared service.
Why it matters
The warnings highlight ongoing phishing risks linked to third-party service compromises in the hardware wallet sector. This development underscores the vulnerability of users to targeted scams exploiting trusted communication channels. The source does not elaborate further on broader market or policy implications.
Key context
Recent incidents involving hardware wallet companies include data breaches at Trezor’s shipping provider ShipMonk, exposing thousands of customers. BitBox previously addressed hardware vulnerabilities unrelated to these phishing events, releasing updates without reported exploitation or fund losses. The phishing warnings follow multiple security disclosures in this industry segment.
Key numbers and entities
Trezor, BitBox, ShipMonk (Trezor’s shipping provider), and Coldcard are named companies. Trezor reported breaches affecting nearly 14,000 customers on Aug. 13 and an additional 67,000 US customers on Sept. 4. There are no specific figures on phishing email reach.
What remains unclear
The source does not clarify the full extent of the breaches or phishing impact, nor confirm whether any users fell victim. Details about the compromised third-party email and newsletter providers and remedial actions taken remain unspecified. Responses from Trezor and BitBox were not available by publication.