
- Trezor and BitBox warned users about phishing emails impersonating their brands after suspected breaches at third-party email and newsletter providers.
- Anyone who shares a recovery seed could lose funds, making phishing instructions dangerous despite wallet security assurances.
- BitBox's investigation continued after it said other Bitcoin companies appeared to share the compromised newsletter provider.
Trezor said its third-party email provider had been breached and reiterated on Sept. 10 that its wallets remained safe.
Trezor identified an email titled “Critical Security Alert: STM32 Entropy Vulnerability” as a . The company said the message did not come from and told recipients not to click any link. The technical-sounding subject was part of the fake security alert, rather than a vulnerability announcement from the wallet maker.
In its Sept. 9 warning, Trezor said it had taken down the domain and was investigating how attackers accessed its legitimate domain. The following day, Trezor and again described the incident as a breach at a third-party email provider.
BitBox issued its own on Sept. 9, telling users not to follow the phishing email's instructions while it investigated. In a subsequent , BitBox said its preliminary review found it very likely that its newsletter provider had been compromised.
also said other Bitcoin companies had been targeted and appeared to share the same newsletter provider. BitBox said it had warned all newsletter subscribers, contacted the provider and reported the phishing domains.
Most phishing links appeared to have been taken down by the time of that update, according to BitBox, which said its investigation was continuing.
Keep recovery seeds private
The warnings concern emails impersonating wallet companies. Trezor's reassurance about its wallets does not make following a phishing message safe: its says anyone who obtains a wallet backup, also called a recovery seed, can move the funds.Trezor tells users never to share that backup and to check official channels if they are concerned about a message or their wallet's security. Its guidance also advises avoiding suspicious links and attachments and downloading Trezor Suite only from its official website.
For recipients, the immediate response is to ignore the phishing emails' instructions and keep recovery words private. Any follow-up about the incident should be checked through the companies' official channels, rather than through links supplied by the suspicious email.
Mentioned in this article
Editorial credits
Curated intelligence, delivered your way.
Never miss a market-moving update.- Daily briefingTop stories & analysis
- Market movesKey charts & data
- Policy updatesWhat to watch
- Weekly deep diveLong-form insights