Crypto wallet makers Trezor and BitBox hit by phishing emails from compromised newsletter service
Trezor and BitBox warned that phishing messages were sent to their newsletter subscribers after the email provider they use was breached.
A breach of the email-marketing platform used by several crypto companies allowed fraudsters to send phishing emails to Trezor and BitBox newsletter subscribers. The counterfeit alerts, titled as critical security warnings about an alleged entropy defect, instruct users to provide their wallet seed backups or refresh API keys. Because the messages originate from the legitimate provider’s domain, they can bypass typical email authentication checks.
Both hardware wallet makers have cautioned users not to interact with the emails and have alerted their communities via official channels. CoinTracking, another crypto service, reported a comparable attack and identified the provider as Brevo. The provider has not commented, and investigations are ongoing.
Why it matters
Compromised newsletter emails could trick crypto users into exposing private keys, risking loss of digital assets.
In this story
