Trezor And BitBox Flag Phishing Attempts Following Suspected Third‑Party Compromises

TL;DR
- Trezor confirmed a breach at its email provider and warned about a fraudulent message titled “Critical Security Alert: STM32 Entropy Vulnerability”.
- BitBox warned that its newsletter provider may have been compromised and that several Bitcoin companies were affected through a shared provider.
- Security incidents at other logistics providers of the company exposed the data of more than 81,000 customers in the U.S.
The hardware wallet sector is going through a high-tension week. Trezor and BitBox jointly warned about phishing emails disguised as urgent security alerts, after compromises were detected in third-party email service providers used by both companies.
Trezor reported that its email provider had been breached and warned its users that a message circulating under the subject “Critical Security Alert: STM32 Entropy Vulnerability” was fraudulent. The company urged recipients to not click on any links included in that email.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
… Continue reading the full article at the original source below.



