Skip to content

Trezor Faces Phishing Attack After Email Breach

Phishing Attacks Target Trezor, BitBox, and CoinTracking Users

  • On Sept. 9, Trezor reported phishing emails sent from a compromised third-party email provider, impersonating the hardware wallet maker.
  • The phishing emails claimed a critical vulnerability in Trezor hardware wallets and passed standard email-authentication checks.
  • BitBox confirmed similar phishing attempts using its branding, warning users about a microcontroller bug.
  • CoinTracking users received fraudulent messages urging them to refresh API keys due to a supposed data breach.
  • Researchers noted potential links to Brevo (formerly Sendinblue), but no breach confirmation was available at the time of reporting.

The incidents highlight vulnerabilities in email marketing infrastructure that can be exploited for phishing campaigns targeting cryptocurrency users. All three companies advised recipients not to click on suspicious links or provide sensitive information.

Trezor’s warning about the phishing attack underscores the importance of vigilance against such threats, especially as these emails appeared legitimate and referenced actual company domains.(Source)

Share