Trezor, BitBox users targeted in newsletter phishing spree

https://image.theregister.com/5240537.jpg?imageId=5240537&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Attackers exploit legitimate mailing channels to demand crypto wallet backups

Crypto hardware wallet maker Trezor Trezor says the third-party email service provider it uses to send newsletters has been breached, and customers are now being sent phishing messages.

There is good and bad news. The good news is that the emails appear easy to spot. They are not bespoke to each recipient and resemble a spray-and-pray campaign rather than sophisticated targeting that uses customer-specific data to enhance the email's perceived authenticity.

All known examples of the scam email are titled "Critical Security Alert: STM32 Entropy Vulnerability," and the body explains that an estimated one in four Trezor devices are affected by a "hardware factory defect."

The email warns customers that wallet seeds are exposed to brute-force attacks due to "insufficient randomness" and a "critically low 40-bit entropy."

The email asks recipients to share their wallet backups. Trezor said: "Do...

Copyright of this story solely belongs to www.theregister.com. To see the full text click HERE

Read more