Breaking
ITEmma Bonino, historic Radical leader and figure in Italian politics, has died in RomeINTLRussian strikes kill seven and wound 76 in Ukraine industrial hub of PavlohradINTLDutch tour bus crash in eastern Switzerland leaves multiple fatalities and injuriesRUOne person was injured during the attack of the Ukrainian Armed Forces on the Samara regionITThe Houthis conquer the last stretch of the Yemeni coast on the Red SeaINTLPhilippine firefighters search smoldering ferry after deadly fireRUAir defenses intercept 777 Ukrainian drones over Russian regions, casualties reportedRUMilitary expert names possible launch sites for AFU drones targeting PermDEDiesel in the USA is more expensive than ever before: a record high of over 6 dollarsTR'C31K' operation in 22 provinces based in Ankara: 27 detainedITEmma Bonino, historic Radical leader and figure in Italian politics, has died in RomeINTLRussian strikes kill seven and wound 76 in Ukraine industrial hub of PavlohradINTLDutch tour bus crash in eastern Switzerland leaves multiple fatalities and injuriesRUOne person was injured during the attack of the Ukrainian Armed Forces on the Samara regionITThe Houthis conquer the last stretch of the Yemeni coast on the Red SeaINTLPhilippine firefighters search smoldering ferry after deadly fireRUAir defenses intercept 777 Ukrainian drones over Russian regions, casualties reportedRUMilitary expert names possible launch sites for AFU drones targeting PermDEDiesel in the USA is more expensive than ever before: a record high of over 6 dollarsTR'C31K' operation in 22 provinces based in Ankara: 27 detained
BackHardware-Wallet Makers Trezor and BitBox Warn Users of Phishing Emails
Hardware-Wallet Makers Trezor and BitBox Warn Users of Phishing Emails
Developing
CryptoSlate9 minutes agoTech1 min read

Hardware-Wallet Makers Trezor and BitBox Warn Users of Phishing Emails

Companies report third-party email provider breaches used to target crypto users with fake security alerts.

Quick Look

  • Hardware-wallet makers Trezor and BitBox warned users on Sept.
  • 9 about phishing emails impersonating their brands following third-party email provider breaches.
  • Both companies urged recipients to avoid suspicious links and keep recovery seeds private.

AI-generated summary

Why It Matters

Hardware-wallet makers Trezor and BitBox suffered third-party email provider breaches leading to phishing campaigns.

Font size

Hardware-wallet makers Trezor and BitBox warned users on Sept. 9 about phishing emails impersonating their brands, urging recipients to avoid the messages' links and instructions.

Trezor said its third-party email provider had been breached and reiterated on Sept. 10 that its wallets remained safe.

Trezor identified an email titled “Critical Security Alert: STM32 Entropy Vulnerability” as a phishing attempt. The company said the message did not come from Trezor and told recipients not to click any link. The technical-sounding subject was part of the fake security alert, rather than a vulnerability announcement from the wallet maker.

In its Sept. 9 warning, Trezor said it had taken down the domain and was investigating how attackers accessed its legitimate domain. The following day, Trezor said its wallets were still safe and again described the incident as a breach at a third-party email provider.

BitBox issued its own impersonation warning on Sept. 9, telling users not to follow the phishing email's instructions while it investigated. In a subsequent update that day, BitBox said its preliminary review found it very likely that its newsletter provider had been compromised.

BitBox also said other Bitcoin companies had been targeted and appeared to share the same newsletter provider. BitBox said it had warned all newsletter subscribers, contacted the provider and reported the phishing domains.

Most phishing links appeared to have been taken down by the time of that update, according to BitBox, which said its investigation was continuing.

Keep recovery seeds private

The warnings concern emails impersonating wallet companies. Trezor's reassurance about its wallets does not make following a phishing message safe: its standing security guidance says anyone who obtains a wallet backup, also called a recovery seed, can move the funds.

Trezor tells users never to share that backup and to check official channels if they are concerned about a message or their wallet's security. Its guidance also advises avoiding suspicious links and attachments and downloading Trezor Suite only from its official website.

For recipients, the immediate response is to ignore the phishing emails' instructions and keep recovery words private. Any follow-up about the incident should be checked through the companies' official channels, rather than through links supplied by the suspicious email.

Open Questions

  • Which third-party email provider was breached?
  • How many users received the phishing emails?
  • Were any funds actually stolen?

Related Topics

This article was originally published by CryptoSlate.

Related Stories

OpenAI's AI agents solve Navier-Stokes problem, with implications for smart-contract security
Developing·

OpenAI's AI agents solve Navier-Stokes problem, with implications for smart-contract security

OpenAI reported that 10,000 concurrent AI agents solved a Navier-Stokes fluid-motion problem in 88 hours, with formal verification in Lean taking another 17 hours using GPT-6 Astra. The breakthrough establishes cases C and D of the Millennium Prize formulation and could automate theorem proving for smart-contract security, reducing labor-intensive verification while increasing the importance of accurate specification design for DeFi protocols and tokenized assets.

CryptoSlate
2 min read
DeepSeek V4.1 Flash nearly matches GPT-6 Astra in design benchmark at 1.4% of the cost
Developing·

DeepSeek V4.1 Flash nearly matches GPT-6 Astra in design benchmark at 1.4% of the cost

OpenDesign Arena benchmarked 13 AI models on real-world design tasks, with GPT-6 Astra scoring highest at 82.7 points and DeepSeek V4.1 Flash close behind at 81.2 points while costing only $0.023 per design versus $1.61 for the leader. DeepSeek's model uses a Causal Encoder-Decoder architecture activating only 8-16 billion of its 552 billion parameters, enabling low cost and fast delivery.

Decrypt
2 min read
Researchers reduce quantum attack resource benchmark for Bitcoin and Ethereum cryptography by 86%
Developing·

Researchers reduce quantum attack resource benchmark for Bitcoin and Ethereum cryptography by 86%

Researchers using AI coding agents reduced the computational resource benchmark for a key step in a potential quantum attack on Bitcoin and Ethereum's cryptography by 86%, lowering the score from 10.75 billion to 1.496 billion in the ECDSA.Fail open competition. The work involved designing and testing a quantum circuit for cracking secp256k1 elliptic curve signatures, though no actual private key was cracked. Researchers note migration to post-quantum cryptography is underway, with NIST proposing to deprecate vulnerable algorithms after 2030.

Decrypt
2 min read
Superfluid Bug Drains Over $100,000 from GoodDollar Reserves via Excess G$ Creation on Celo
Developing·

Superfluid Bug Drains Over $100,000 from GoodDollar Reserves via Excess G$ Creation on Celo

A vulnerability in Superfluid's Celo deployment allowed an attacker to bypass liquidation safeguards, create excess G$ tokens, and drain over $100,000 from GoodDollar's reserves on Celo and XDC networks. GoodDollar reported 86,588 cUSD and $20,857 withdrawn, with external liquidity pools also affected. Both projects paused operations and are preparing incident reports to explain the cross-network impact.

CryptoSlate
2 min read
More on this topictrezor