Meta Force Space
BTC $76,862.00 -1.37% ETH $2,462.46 -0.09% SOL $99.06 -1.74% XRP $1.34 -2.62% BNB $711.19 -0.62% DOGE $0.0834 -1.67%
← Back to the news

Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders

Hardware-wallet makers Trezor and BitBox warned users on Sept. 9 about phishing emails impersonating their brands, urging recipients to avoid the messages' links and instructions.

Trezor said its third-party email provider had been breached and reiterated on Sept. 10 that its wallets remained safe.

Trezor identified an email titled “Critical Security Alert: STM32 Entropy Vulnerability” as a phishing attempt. The company said the message did not come from Trezor and told recipients not to click any link. The technical-sounding subject was part of the fake security alert, rather than a vulnerability announcement from the wallet maker.

In its Sept. 9 warning, Trezor said it had taken down the domain and was investigating how attackers accessed its legitimate domain. The following day, Trezor said its wallets were still safe and again described the incident as a breach at a third-party email provider.

BitBox issued its own impersonation warning on Sept. 9, telling users not to follow the phishing email's instructions while it investigated. In a subsequent update that day, BitBox said its preliminary review found it very likely that its newsletter provider had been compromised.

BitBox also said other Bitcoin companies had been targeted and appeared to share the same newsletter provider. BitBox said it had warned all newsletter subscribers, contacted the provider and reported the phishing domains.

Most phishing links appeared to have been taken down by the time of that update, according to BitBox, which said its investigation was continuing.

Related Reading

SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft

Keep recovery seeds private

The warnings concern emails impersonating wallet companies. Trezor's reassurance about its wallets does not make following a phishing message safe: its standing security guidance says anyone who obtains a wallet backup, also called a recovery seed, can move the funds.

Trezor tells users never to share that backup and to check official channels if they are concerned about a message or their wallet's security. Its guidance also advises avoiding suspicious links and attachments and downloading Trezor Suite only from its official website.

For recipients, the immediate response is to ignore the phishing emails' instructions and keep recovery words private. Any follow-up about the incident should be checked through the companies' official channels, rather than through links supplied by the suspicious email.

Originally published by CryptoSlate on

Read the original on CryptoSlate ↗

Text and images are the property of CryptoSlate and are reproduced here with attribution and a link to the original publication.

More stories

All the latest news