BitcoinNews on Nostr: WARNING: TREZOR AND BITBOX USERS TARGETED IN EMAIL PHISHING ATTACK Trezor and BitBox ...
WARNING: TREZOR AND BITBOX USERS TARGETED IN EMAIL PHISHING ATTACK
Trezor and BitBox users are being targeted with fake “Critical Security Alert” emails claiming an STM32 microcontroller entropy vulnerability has compromised wallet recovery phrases.
Trezor says its third-party email provider was breached, allowing attackers to send phishing emails appearing to come from its legitimate domain.
The emails direct users to a fake “entropy check” tool.
Trezor says the domain has been taken down and it is investigating how the attackers gained access.
Do NOT click the links or enter your recovery phrase anywhere.
Published at
2026-09-10 03:23:52 UTCEvent JSON
{
"id": "b6971d68104710454928e016c4a2c2ea597d3448447d5420dc9eb3889dafd373",
"pubkey": "2774d83c8f9789c583414292b1192c4345db7ff0d551ea32efa2958f4192f6e5",
"created_at": 1789010632,
"kind": 1,
"tags": [
[
"imeta",
"url https://image.nostr.build/b64d7ab9ef771408c0fe174b0f851be312953ffdc803b71c8273ee05b5d09290.jpg",
"blurhash emP6,Ss:xuWBt74Us:ofWBoyVYf5a}jtkC?GaxWBofWV-pfPWVofWB",
"dim 1330x1446"
],
[
"imeta",
"url https://image.nostr.build/d7a9e0ea1ed8ec5b03d675e220434aa43e6c82f5d3c56cca35ad0ad10195011b.jpg",
"blurhash e35}z3xu4mRjM{D%Rjt7t7t8D%of%NWBRjD%ay%Mj[ayafayRjayt8",
"dim 824x1200"
],
[
"r",
"https://image.nostr.build/b64d7ab9ef771408c0fe174b0f851be312953ffdc803b71c8273ee05b5d09290.jpg"
],
[
"r",
"https://image.nostr.build/d7a9e0ea1ed8ec5b03d675e220434aa43e6c82f5d3c56cca35ad0ad10195011b.jpg"
],
[
"client",
"Damus"
]
],
"content": "WARNING: TREZOR AND BITBOX USERS TARGETED IN EMAIL PHISHING ATTACK\n\nTrezor and BitBox users are being targeted with fake “Critical Security Alert” emails claiming an STM32 microcontroller entropy vulnerability has compromised wallet recovery phrases.\n\nTrezor says its third-party email provider was breached, allowing attackers to send phishing emails appearing to come from its legitimate domain.\n\nThe emails direct users to a fake “entropy check” tool.\n\nTrezor says the domain has been taken down and it is investigating how the attackers gained access.\n\nDo NOT click the links or enter your recovery phrase anywhere.\n\nhttps://image.nostr.build/b64d7ab9ef771408c0fe174b0f851be312953ffdc803b71c8273ee05b5d09290.jpg\nhttps://image.nostr.build/d7a9e0ea1ed8ec5b03d675e220434aa43e6c82f5d3c56cca35ad0ad10195011b.jpg",
"sig": "bddefc7f34eac4b94d16ad7c9f54f21fd4f5093e3438b4c81fed3d87df4937f7988abaea6ed01b87e524ef662afc45b8dac5f012730c8cf9e6a8310214c8aed8"
}