- Trezor warned on September 9 that attackers used a compromised third-party email provider to send users a phishing email posing as a critical security alert.
- The fake message falsely claimed a hardware flaw in the STM32 chips inside Trezor devices could weaken recovery phrases; Trezor took down the domain and said keys and funds were not exposed.
- BitBox reported the same scam the same day, saying its newsletter provider was “very likely” compromised and that several Bitcoin firms shared it; neither company named the provider.
Hardware wallet maker Trezor warned users on September 9 that attackers had used a compromised third-party email provider to send a phishing email disguised as a critical security alert, part of a wave that also reached rival BitBox and other Bitcoin companies.
The fraudulent email, titled “Critical Security Alert: STM32 Entropy Vulnerability”, was sent through Trezor’s own provider, so it passed the checks that flag spoofed senders and reached inboxes from what looked like a genuine Trezor address.
“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt”, the company posted on X, telling users not to click any link. Trezor said it had taken down the domain behind the campaign and was investigating how the attackers reached its email channel.
Read more: Ripple Brings XRP Branding to Florida Football
A Fake Chip Vulnerability
The message claimed Trezor engineers had found a critical hardware flaw in the STM32 microcontrollers inside its devices, one it said affected roughly one in four, that could leave a wallet’s recovery phrase with too little randomness, or entropy.
Trezor disclosed no such flaw. STM32 is the chip family its wallets are built around, and the recovery phrase is the backup that restores access to funds, so a real entropy defect would be serious. Scams of this kind work by frightening holders into typing that phrase into a fake page or app, which lets an attacker drain the wallet.
Trezor said no wallets, keys or recovery backups were exposed, and told users to ignore the message.
BitBox reported the same scam within hours. “It is very likely that our newsletter provider got compromised”, the Swiss company said, adding that several other Bitcoin firms were targeted and appeared to use the same provider. Its version of the email carried a near-identical subject line about a microcontroller “entropy vulnerability”. Neither company named the provider that was breached.
Trezor’s customers were phished the same way in 2022, when attackers exploited the company’s MailChimp newsletter list. Similar recovery-phrase scams have since hit users of Ledger and MetaMask.
BitBox likewise said its BitBox02 devices, its app and customer funds were unaffected, and repeated its standing advice never to enter recovery words anywhere but the device itself.
Related: XRP Ledger Holds More Value as RLUSD Growth Accelerates
Hackers,Trezor#Trezor #Email #Provider #Breached #Phishing #Attack #Targeting #Crypto #Users1789018464
