
Manufacturers of hardware wallets Trezor and BitBox have issued warnings to users about phishing emails that disguise themselves as urgent security notifications. The reason for this is the alleged compromises of third-party email services serving these companies.
On Wednesday, Trezor reported that its email provider had been hacked. The company warned that an email titled "Critical Security Alert: STM32 Entropy Vulnerability" is a fake and urged recipients not to click on any links. On the same day, BitBox issued a similar warning about a phishing email that posed as a message from the company. Preliminary reports suggest that BitBox's newsletter provider was likely compromised, and several Bitcoin companies appear to have been targeted through a common provider.
These warnings are a continuation of a series of recent incidents in the hardware wallet sector. On August 13, a leak at ShipMonk, Trezor's shipping partner, affected data from nearly 14,000 customers. On September 4, Trezor reported that another 67,000 customers from the U.S. were affected. Separately, in July, BitBox stated that its devices were not affected by the vulnerability related to random number generation in Coldcard. In August, the company released an update addressing two critical firmware vulnerabilities. There have been no known cases of exploitation of these vulnerabilities or reports of stolen user funds.

