Hardware wallet makers Trezor and BitBox warned users about phishing emails disguised as urgent security notices after suspected compromises involving third-party email services. Trezor confirmed its email provider was breached and flagged a fraudulent message titled « Critical Security Alert: STM32 Entropy Vulnerability ». BitBox said its newsletter provider was likely compromised, with multiple Bitcoin companies appearing to have been targeted through a shared provider. The sector has faced multiple recent security incidents, including a breach at Trezor shipping provider ShipMonk exposing data belonging to nearly 14,000 customers in August, followed by disclosure that another 67,000 US customers were affected in September.
Source: Read the original article

