Trezor and BitBox Warn of Phishing Campaign Using Legitimate Domains
Attackers breached a third-party email provider to send fraudulent security alerts that bypassed standard authentication filters.
Hardware wallet manufacturers Trezor and BitBox have issued urgent warnings to their users following a coordinated phishing campaign that utilized legitimate communication channels to steal funds. The attack is notable for its sophistication, as it bypassed standard email authentication protocols to appear authentic.
Attackers breached Trezor's third-party email provider, allowing them to send fraudulent emails directly from Trezor's official domain. Because the messages originated from legitimate infrastructure, they successfully passed SPF, DKIM, and DMARC security checks. These emails featured the subject line "Critical Security Alert: STM32 Entropy Vulnerability," designed to create a sense of immediate panic and trick users into visiting a malicious website.
The Technical Hook
The attackers specifically referenced the STM32 family of microcontrollers used in Trezor devices. By claiming a vulnerability in "entropy"—the randomness used to generate a wallet's recovery phrase—the campaign targeted a fundamental security pillar of cold storage. A genuine entropy vulnerability would theoretically make recovery phrases predictable, potentially allowing an attacker to steal funds without physical access to the device. By using this specific technical claim, the attackers aimed to convince cautious users that their hardware security was compromised and required immediate action.
A Coordinated Effort
While Trezor was a primary target, BitBox users were also targeted in a similar phishing campaign. The simultaneous nature of these attacks suggests a coordinated effort targeting hardware wallet users. This pattern indicates a strategic attempt to undermine trust in hardware wallet ecosystems by exploiting the trust users place in official brand communications.
Systemic Risks in Cold Storage
This incident highlights a critical vulnerability in the "cold storage" philosophy. While hardware wallets keep private keys offline and safe from direct digital theft, the communication channels users trust to receive updates remain a significant point of failure. Because these emails originated from legitimate infrastructure, they bypassed the filters that typically flag phishing attempts, proving that third-party service providers can become a backdoor into the security of even the most cautious investors.
What to Watch
Users are reminded that legitimate hardware wallet manufacturers will never ask for a recovery seed phrase via email or on a website. As the industry analyzes the breach of the third-party email provider, the focus will likely shift toward how crypto firms manage their external vendor risks. It remains to be seen if other hardware wallet providers were targeted in this same wave of attacks.