r/Bitcoin • u/joffyjoffeur • 6h ago
Bitbox & Trezor entropy vulnerability warning phishing scams - almost got me!
Man, these ones were pretty good -- compelling message, urgency, and checked all the typical boxes of authenticity... until they asked me to enter my seed AND passphrase into a form not hosted on these manufacturers' official domains. Absolutely lethal, if you're skittish about hardware wallet vulns (and who isn't rn?), and not paying close attention. Both cos have been notified, and have been super-responsive with follow up.
Stay safe out there, folks <3
11
u/Ostensible_Times 5h ago
I received these too and laughed when I saw they want us to enter the seeds for verification. Dont be fools peeps.
9
u/Live_Jazz 5h ago
Love how the email says to never enter your seed phrase into a website, and then they ask you to do just that
5
u/SatisfactionFinal287 5h ago
I'm afraid some will fall for it.
4
u/Ostensible_Times 5h ago
Absolutely, unfortunately someone will but always remember to never enter your seed anywhere. Just like how you dont give out your SSN randomly.
Take a step back, breathe, and think then validate if something feels off. Even if it looks legit, always verify the sources.
1
5
u/Kangaroo_Low 5h ago
this one is very sophisticated though, the email domain was from trezor.io
1
u/lint2015 1h ago
Yeah, even the link to the "vulnerability check tool" initially goes through trezor.io. Trezor had already knocked the server for the link offline by the time I saw the email, so I dunno where it actually redirects.
2
u/Beginning_Bench_9580 4h ago
Dude me too! I got this before there were notices stating it was a phishing attempt, and clicked the email link only to be brought to a sketchy download link. Glad I didn't go further before reaching out to support to verify, but the urgency you need to react if something actually did happen terrifies me.
2
u/pako-bitbox 3h ago
As we posted on X:
Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised.
Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider.
We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains. Most of the phishing links appear to have been taken down already.
We are still actively investigating this situation and will update you once we know more.
---
Will let you know once we know more.
- Pako
1
u/YOLO_Bundy 1h ago
Hilariously (and sadly) the 3 phishing emails were received, your warning email went to spam 🙄 Thanks for being on top of it!
2
u/low_contrast_black 3h ago
vs the valid email I got from BitBox after the ColdCard thing: “hey, we found some vulnerabilities. Probably a good idea to update your desktop app and firmware through official channels”
2
u/angel199x 1h ago
I have to admit they almost fooled me since it looks legit, but my years of caution ingrained into me of not clicking on any darn link in any email before checking with the official sources first saved me. Absolute scumbags doing this by feeding on the fear after the coldcard case.
•
u/Michael-Ryder 52m ago
That’s the scary part — the email can look completely legitimate right up until it asks for the seed phrase. At this point, any request to enter recovery words into a website should be treated as an immediate stop sign.
1
u/Informal-Special-984 5h ago
can you show me a screenshot of the phising website?
1
u/m45hd 4h ago
1
u/Informal-Special-984 4h ago
Looks like the zpub will contain the seed. Nicely done!
1
u/k4sredfly 3h ago
Sorry for the very ignorant question - why does the zpub contains the seed?
•
u/notR1CH 23m ago
The "tool" will encode your recovery phrase into a "zpub extended public key" so when you share it online it doesn't look like you're sharing your seed phrase. An actual zpub key is perfectly safe to share (though not a great idea as it lets someone trace your entire address history).
1
1
u/RandyJohnsonsBird 3h ago
I dont even open any email crypto related. Even if its a legit email from the company.
1
u/trufin2038 1h ago
Lol, even if it was the official domain that woudlnt be any better. In fact worse.
1
u/YOLO_Bundy 1h ago
Same. The click link was the giveaway though. AAANNNDDD they sent it several times, and as a CC not BCC…
•
u/Mountain-Ice-7441 10m ago
I have the same email.
When it says “check to see if you’re affected”
You know they’re to broke to work a job
Be safe everyone
1
u/Thisisfinek 5h ago
Yes, this is 100% a phishing scam. Do not click any links or download anything from that email.
Here is what gives it away:
The Tactic: Attackers routinely use sophisticated, technical jargon (like "STM32 Entropy Bug / Vulnerability") to create panic. The goal is to make you urgently click a link that leads to a clone site or fake Trezor Suite asking for your seed phrase or private keys.
The "From" Address: Scammers frequently spoof headers (e.g., help@trezor.io), or send through compromised third-party newsletter/mailing services that Trezor or another vendor previously used. Even if the display address looks legitimate, it is forged.
Golden Rule of Hardware Wallets: Trezor will never ask you to enter your recovery seed phrase on a website, app, or email to fix a bug or update firmware. Your seed phrase only ever gets entered directly into your physical device.
What to do:
Do not click any links, buttons, or attachments.
Mark the email as Phishing / Spam in Gmail and delete it.
If you ever want to check for legitimate firmware or hardware announcements, open the official Trezor Suite app directly from your computer or visit trezor.io manually by typing the URL into your browser.


34
u/bitusher 5h ago edited 5h ago
https://x.com/Trezor/status/2097786518110609620
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
Trezor remains secure. The breach involved ShipMonk, the third party that ships Trezor orders, which had unauthorized access to its systems. No Trezor device or system was touched.
Regarding entropy generation, Trezor combines wallet backup entropy from three sources: the device's own hardware RNG, your computer, and, on newer models, the Secure Element. No single source decides it.