Key Takeaways

  • Hackers are using compromised email infrastructure to send convincing security alerts to Bitcoin users.

  • Fake hardware wallet warnings attempt to trick users into entering their recovery seed phrases.

  • Trezor and BitBox devices were not reported compromised, but users should avoid links in suspicious emails.

Bitcoin Users Face a New Phishing Threat

Users of several Bitcoin companies, including major hardware wallet brands, are being targeted by a phishing campaign that utilizes security warnings to trick the users into revealing sensitive information.

The campaign appears to be linked to a breach at a third-party email provider used by several Bitcoin companies. Instead of breaking into users' wallets directly, attackers used trusted email systems to send messages that looked like legitimate security alerts.

Trezor warned customers about an email titled “Critical Security Alert: STM32 Entropy Vulnerability.” The message falsely claimed that a serious hardware problem could affect the security of Trezor devices and their recovery phrases.

The email appears to be a legit message from Trezor (Click for higher resolution) — Reddit

Trezor said the email did not come from the company.

“Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link,” Trezor said.

The fake message claimed that around one in four Trezor devices had a hardware defect that could result in weak randomness, or entropy. It then encouraged users to check their devices through a website, which was controlled by the attackers.

The messages attempted to create a sense of urgency and directed recipients toward a website described as an “entropy check” tool. Users were encouraged to enter their seed phrases there to “check” their wallets.

The goal was simple: make users worried that their bitcoin could be at risk and convince them to take action. The campaign was more dangerous because the attackers appear to have gained access to a legitimate email provider used by Trezor.

Normally, users can look at an email address and other security information to help decide whether a message is genuine. But if attackers are able to send messages through a company's legitimate mailing infrastructure, those checks become less useful.

Trezor said its third-party email provider had been breached. The company took down the malicious domain and began investigating how the attackers gained access.

The provider was not initially named by Trezor. However, Brevo, a major email and marketing platform, later said that a security incident had allowed an attacker to access 120 customer accounts. The attacker then used some of those accounts to send phishing emails.

It is not yet known whether the two incidents are connected or not.

“Never enter your wallet backup anywhere,” the company warned, advising users to confirm important actions directly through their physical Trezor device.

The attack was not limited to Trezor.

Swiss Bitcoin hardware wallet maker BitBox reported that its newsletter subscribers had received a similar phishing email. The message used a slightly different title, “Critical Security Alert: Microcontroller Entropy Bug Identified,” but used the same basic trick.

Phishing email sent to BitBox users (click for higher resolution) — Reddit

BitBox said its preliminary investigation indicated that its newsletter provider had probably been compromised.

“Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider,” the company said.

BitBox contacted the provider, warned its customers and reported the phishing domains. It said most of the malicious links had already been taken down while the investigation continued.

Bitcoin portfolio and tax platform CoinTracking also reported being affected. Its customers received a fake message asking them to refresh their API keys. CoinTracking identified Brevo as the third-party provider involved in its incident.

There has also been reports of a similar incident for Mercury users, a digital assets payment platform.

Together, the reports suggest that attackers were targeting companies through a shared email infrastructure rather than attacking each company separately.

There is an important distinction between the email breach and a direct wallet hack.
There is no indication from the reports that Trezor or BitBox devices themselves were compromised, or that users' private keys or recovery phrases were stolen through the incident.

If a message claims that your hardware wallet has a serious security problem, check the company's official website or verified social media accounts separately. Do not use the links or contact information provided in the suspicious message.

The incident is a reminder that Bitcoin users do not only need to protect their wallets. They also need to protect the information and communication channels surrounding those wallets.

100% of the sats go directly to the author

Latest on YouTube


Reply

Avatar

or to participate