Trezor, BitBox users targeted in newsletter phishing spree
Crypto hardware wallet maker Trezor says the third-party email service provider it uses to send newsletters has been breached, and customers are now being sent phishing messages.
There is good and bad news.
The good news is that the emails appear easy to spot.
They are not bespoke to each recipient and resemble a spray-and-pray campaign rather than sophisticated targeting that uses customer-specific data to enhance the email's perceived authenticity.
All known examples of the scam email are titled "Critical Security Alert: STM32 Entropy Vulnerability," and the body explains that an estimated one in four Trezor devices are affected by a "hardware factory defect." The email warns customers that wallet seeds are exposed to brute-force attacks due to "insufficient randomness" and a "critically low 40-bit entropy." The email asks recipients to share their wallet backups.
Trezor said: "Do not click it or interact with it.
Never enter your wallet backup anywhere.
Always confirm every action with your Trezor physically." The bad news is that because the attackers allegedly compromised the legitimate email provider, the messages can pass authentication checks and bypass some of the usual protections deployed by receiving email services.
According to those who have shared copies of the emails, they appear to be sent from "[email protected]." Trezor has issued the warning across its social media channels and Trezor Suite, the companion app for its hardware wallets.
The Register asked Trezor for more information.
The third party email provider Brevo – formerly known as Sendinblue – said in a statement that a "security incident" had "allowed an attacker to access 120 Brevo accounts." It added that the "bad actor used the access to send phishing emails to the client's contactbase," and promised a "full post mortem later today." Swiss hardware wallet maker BitBox also appears to be affected, having shared an image of an email nearly identical to the one targeting Trezor's newsletter subscribers.
The email similarly warns of entropy weaknesses affecting BitBox devices, although it is titled slightly differently: "Critical Security Alert: Microcontroller Entropy Bug Identified." The company said on X: "Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised.
"Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider.
"We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.