A shared newsletter/e-mail provider used by multiple Bitcoin hardware wallet companies was compromised, letting attackers send phishing e-mails from the companies' legitimate domains. Trezor warned that an e-mail titled 'Critical Security Alert: STM32 Entropy Vulnerability' did not originate from them and took down the compromised domain. BitBox confirmed a phishing e-mail was sent to its newsletter subscribers about an hour earlier and, after preliminary review, found it very likely that the shared newsletter provider was compromised, noting multiple other Bitcoin companies were targeted as well. Both companies warned their subscribers, contacted the provider, and reported the phishing domains; most phishing links have since been taken down. Both are still investigating.
Impact
- Funds: Not Affected
- Category: Phishing Related