Loading prices…
🩸BEARISH

Trezor, BitBox Users Hit by STM32 Phishing Attack

Wallets remain safe, but a third-party newsletter breach exposed email lists across multiple Bitcoin firms. The danger is in following the email's recovery-seed instructions.

Trezor and BitBox, two of the largest hardware-wallet makers serving retail Bitcoin holders, issued parallel warnings on Sept. 9 about phishing emails impersonating their brands. The messages carried the technical subject "Critical Security Alert: STM32 Entropy Vulnerability" and asked recipients to follow links and instructions that both firms say they never sent. Trezor confirmed on Sept. 10 that a third-party email provider had been breached, took down the phishing domain, and reiterated that the wallets themselves remain safe.

Why it matters

Hardware-wallet phishing has accelerated alongside the value locked into self-custody, and the attack surface now extends well beyond firmware. BitBox said its preliminary review found its newsletter provider "very likely" compromised, and that other Bitcoin companies appeared to share the same provider, widening the blast radius across the industry. Trezor's standing guidance remains the operative line of defense: anyone who obtains a wallet backup, also called a recovery seed, can move the funds, so following instructions from an unsolicited email is the only way a user becomes exposed. The technical-sounding subject line borrowed the credibility of an actual vulnerability disclosure to lower the recipient's guard.

Market impact

Most phishing links had been taken down by the time of BitBox's update. BitBox has warned all newsletter subscribers, contacted the compromised provider and reported the phishing domains. Trezor advises users to download Trezor Suite only from its official website and to verify any alert through official channels rather than via links in the suspicious message. The episode lands in the same quarter as the SafePal breach that exposed roughly 40,000 customers, suggesting supply-chain risk for hardware-wallet makers now runs through email-list infrastructure as much as through silicon.

Related tokens
$BTC

Frequently asked questions

  1. What exactly did the phishing emails claim?

    They carried the subject "Critical Security Alert: STM32 Entropy Vulnerability" and asked recipients to follow links and instructions that both Trezor and BitBox say they never sent.

  2. Were the hardware wallets themselves hacked?

    No. Trezor confirmed on Sept. 10 that the wallets remain safe. The breach occurred at a third-party email provider, not in the wallet firmware.

  3. What should recipients of the email do next?

    Ignore the instructions, do not click any links, and verify any alert through Trezor and BitBox's official channels rather than via the suspicious message.

  4. Why are recovery seeds central to the risk?

    Anyone who obtains a wallet backup, also called a recovery seed, can move the funds. Following instructions from an unsolicited email is the only way a user becomes exposed.

  5. Were other Bitcoin companies affected too?

    BitBox said its preliminary review found its newsletter provider "very likely" compromised, and that other Bitcoin companies sharing the same provider were also targeted.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →