Trezor, BitBox users targeted in newsletter phishing spree
Attackers exploit legitimate mailing channels to demand crypto wallet backups
Crypto hardware wallet manufacturers Trezor and BitBox have warned customers about a phishing campaign targeting their newsletter subscribers. The emails falsely claim an estimated one in four Trezor devices is affected by a factory defect, urging recipients to share their wallet backups. However, experts advise against clicking or interacting with the emails, emphasizing that users should always confirm actions with their Trezor hardware wallets physically.
The emails appear to be sent from mailing@trezor.io, potentially passing authentication checks due to the alleged compromise of Trezor's email provider. BitBox's newsletter subscribers also received similar phishing messages, which warn of entropy weaknesses in BitBox devices. CoinTracking, a crypto tax and portfolio-tracking company, disclosed a similar compromise of its third-party email provider around the same time.
The involved email provider, Brevo, formerly Sendinblue, has not publicly commented on the alleged connection to the phishing campaigns.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Trezor, BitBox users targeted in newsletter phishing spree theregister.com