Hardware-wallet makers Trezor and BitBox issued warnings to users on September 9 regarding phishing emails impersonating their brands. The emails contained misleading links and instructions, prompting the companies to advise recipients to avoid engaging with the messages.
Trezor disclosed that its third-party email provider had been compromised, leading to the dissemination of phishing emails. Despite this breach, Trezor assured users on September 10 that their wallets remained secure. The company identified a specific email titled “Critical Security Alert: STM32 Entropy Vulnerability” as a phishing attempt and emphasized that it did not originate from Trezor. Recipients were strongly advised not to click on any links provided in the fraudulent email.
Following the incident, Trezor took swift action by taking down the phishing domain and launching an investigation into how the attackers gained access to their legitimate domain. The next day, Trezor reiterated that their wallets were unaffected and clarified that the breach occurred at a third-party email provider.
Similarly, BitBox also issued a warning to users on September 9, cautioning them against following the instructions in the phishing emails. The company indicated that their newsletter provider may have been compromised and initiated an investigation into the matter. BitBox noted that other Bitcoin companies had also been targeted in a similar fashion, suggesting a common link through the newsletter provider. The company promptly alerted all newsletter subscribers, contacted the provider, and reported the phishing domains.
Most of the phishing links had been deactivated by the time of BitBox’s update, signaling progress in their investigation. The company assured users that they were continuing to look into the matter to prevent any further breaches.
The importance of keeping recovery seeds private was emphasized in light of these phishing attempts. Trezor reiterated its security guidance, emphasizing the significance of safeguarding wallet backups and recovery seeds. Users were advised to refrain from sharing this sensitive information and to verify the authenticity of any communication through official channels. Additionally, caution was urged against clicking on suspicious links or downloading software from unverified sources.
In conclusion, recipients of phishing emails should ignore any instructions provided and prioritize the protection of their recovery seeds. Any concerns or queries related to the incident should be addressed through official communication channels provided by the respective companies, rather than responding to links in suspicious emails. It is crucial for users to remain vigilant and proactive in safeguarding their assets and personal information in the ever-evolving landscape of cybersecurity threats.
