Technology
Trezor, BitBox users targeted in newsletter phishing spree
Key Points
Crypto hardware wallet maker Trezor Trezor says the third-party email service provider it uses to send newsletters has been breached, and customers are now being sent phishing messages. There is good and bad news. The good news is that the emails appear easy to spot.
Crypto hardware wallet maker Trezor Trezor says the third-party email service provider it uses to send newsletters has been breached, and customers are now being sent phishing messages. There is good and bad news. The good news is that the emails appear easy to spot. They are not bespoke to each recipient and resemble a spray-and-pray campaign rather than sophisticated targeting that uses customer-specific data to enhance the email's perceived authenticity. All known examples of the scam email are titled "Critical Security Alert: STM32 Entropy Vulnerability," and the body explains that an estimated one in four Trezor devices are affected by a "hardware factory defect." The email warns customers that wallet seeds are exposed to brute-force attacks due to "insufficient randomness" and a "critically low 40-bit entropy." The email asks recipients to share their wallet backups. Trezor said: "Do not click it or interact with it. Never enter your wallet backup anywhere. Always confirm every action with your Trezor physically." The bad news is that because the attackers allegedly compromised the legitimate email provider, the messages can pass authentication checks and bypass some of the usual protections deployed by receiving email services. According to those who have shared copies of the emails, they appear to be sent from "[email protected]." Trezor has issued the warning across its social media channels and Trezor Suite, the companion app for its hardware wallets. The Register asked Trezor for more information. Swiss hardware wallet maker BitBox also appears to be affected, having shared an image of an email nearly identical to the one targeting Trezor's newsletter subscribers. The email similarly warns of entropy weaknesses affecting BitBox devices, although it is titled slightly differently: "Critical Security Alert: Microcontroller Entropy Bug Identified." The company said on X: "Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised. "Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider. "We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains. Most of the phishing links appear to have been taken down already. "We are still actively investigating this situation and will update you once we know more." Neither Trezor nor BitBox named the allegedly compromised provider. However, their respective privacy policies identify Brevo, formerly Sendinblue, as a newsletter provider (see Trezor's here and Bitbox's here). Crypto tax and portfolio-tracking company CoinTracking also disclosed the compromise of its third-party email provider around the same time as Trezor and BitBox. Unlike Trezor and BitBox, CoinTracking identified the provider as Brevo. CoinTracking shared a copy of the phishing email targeting its users and, since it does not offer hardware wallets, the message uses a different lure, asking customers to follow a link to refresh their API keys. Brevo has not publicly commented on its alleged connection to the campaigns. The Register contacted the company for more information. Tough times in Trezorland The latest security snafu comes less than a month after Trezor announced that thousands of customers' details had been compromised following a breach at logistics partner ShipMonk. The hardware vendor initially estimated that around 13,000 people were affected. Those who ordered Trezor products between May 10 and August 8 had their names, email addresses, phone numbers, and shipping addresses breached. Compounding the problem for a company whose brand centers on security, Trezor confirmed on September 4 that the total number of affected customers had risen to 80,000. Trezor said ShipMonk later informed it that an additional 67,000 US customers who purchased products between November 2019 and August 2021 were affected. "Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," said Trezor. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems." ®