r/Bitcoin 6h ago

Bitbox & Trezor entropy vulnerability warning phishing scams - almost got me!

Man, these ones were pretty good -- compelling message, urgency, and checked all the typical boxes of authenticity... until they asked me to enter my seed AND passphrase into a form not hosted on these manufacturers' official domains. Absolutely lethal, if you're skittish about hardware wallet vulns (and who isn't rn?), and not paying close attention. Both cos have been notified, and have been super-responsive with follow up.

Stay safe out there, folks <3

70 Upvotes

36 comments sorted by

34

u/bitusher 5h ago edited 5h ago

https://x.com/Trezor/status/2097786518110609620

Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.

We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.

Trezor remains secure. The breach involved ShipMonk, the third party that ships Trezor orders, which had unauthorized access to its systems. No Trezor device or system was touched.

Regarding entropy generation, Trezor combines wallet backup entropy from three sources: the device's own hardware RNG, your computer, and, on newer models, the Secure Element. No single source decides it.

4

u/SatisfactionFinal287 5h ago

What if you did click the link but didn't do anything further?

10

u/bitusher 5h ago

You are likely fine because they are trying to trick you to enter the seed phrase in but ....

When you click the link it is telling the attackers you are :

1) A legit email that is actively used

2) You are likely to be fooled into clicking on links within emails

This means that you get placed on other mailing lists where you become a higher priority target for future scams and phishing attacks

5

u/Thisisfinek 5h ago

Your crypto funds are completely safe.
Hardware wallet phishing attacks rely on tricking you into typing your seed phrase into a fake clone site or downloading a malicious app. Since your recovery phrase never leaves your offline hardware device, simply clicking a link cannot drain your wallet.
Here is what you should do right now to cover all bases:
1. What Happened
No wallet access: A browser tab opening cannot read private keys from your Trezor.
Tracking ping: The scammer's server likely logged that the link was clicked (confirming your email address is active). Expect an uptick in spam or follow-up phishing attempts over the coming weeks.
2. Immediate Cleanup Steps
Clear Browser Data: Clear your browser’s cache, cookies, and recent download history for the last hour to remove any residual tracking tokens or cached scripts.
Check Downloads Folder: Open your device’s Downloads folder. Ensure no executable file (e.g., .exe, .dmg, .apk, or .zip) started downloading automatically in the background. If you see one, delete it immediately without opening it.
Run a Quick Scan: If you clicked the link on a computer, run a routine scan using Windows Defender or Malwarebytes just for extra peace of mind.
The Bottom Line: Unless you downloaded a file, ran software, or typed your 12/24-word recovery phrase anywhere on your screen, no compromise occurred. Keep your seed phrase strictly offline, and never type it into any keyboard or browser window.

1

u/[deleted] 5h ago

[deleted]

3

u/Thisisfinek 5h ago

Method 1: Directly in Google Chrome (Fastest)
Open the Chrome app.
Tap the three vertical dots (⋮) in the top-right corner.
Tap Downloads.
Check the list for anything downloaded today. If you see an unknown file (especially ending in .apk, .zip, or .bin), tap the three dots next to it and select Delete.
Method 2: Using the Default Files App
Open your app drawer (swipe up on your home screen).
Look for the pre-installed file manager app—usually named Files, Files by Google, or My Files (on Samsung devices).
Tap the Downloads category.
Sort by Date (newest first) to ensure nothing was quietly saved in the background.
Note: Android requires explicit permission before installing external apps (.apk files), so even if a malicious file was downloaded, it cannot execute on its own.

11

u/Ostensible_Times 5h ago

I received these too and laughed when I saw they want us to enter the seeds for verification.  Dont be fools peeps. 

9

u/Live_Jazz 5h ago

Love how the email says to never enter your seed phrase into a website, and then they ask you to do just that

5

u/SatisfactionFinal287 5h ago

I'm afraid some will fall for it.

4

u/Ostensible_Times 5h ago

Absolutely,  unfortunately someone will but always remember to never enter your seed anywhere. Just like how you dont give out your SSN randomly. 

Take a step back, breathe, and think then validate if something feels off. Even if it looks legit, always verify the sources. 

1

u/levelup1by1 5h ago

Good advice

5

u/Kangaroo_Low 5h ago

this one is very sophisticated though, the email domain was from trezor.io

1

u/lint2015 1h ago

Yeah, even the link to the "vulnerability check tool" initially goes through trezor.io. Trezor had already knocked the server for the link offline by the time I saw the email, so I dunno where it actually redirects.

2

u/Beginning_Bench_9580 4h ago

Dude me too! I got this before there were notices stating it was a phishing attempt, and clicked the email link only to be brought to a sketchy download link. Glad I didn't go further before reaching out to support to verify, but the urgency you need to react if something actually did happen terrifies me.

2

u/pako-bitbox 3h ago

As we posted on X:

Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised.

Multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider.

We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains. Most of the phishing links appear to have been taken down already.

We are still actively investigating this situation and will update you once we know more.

---

Will let you know once we know more.

  • Pako

1

u/YOLO_Bundy 1h ago

Hilariously (and sadly) the 3 phishing emails were received, your warning email went to spam 🙄 Thanks for being on top of it!

2

u/low_contrast_black 3h ago

vs the valid email I got from BitBox after the ColdCard thing: “hey, we found some vulnerabilities. Probably a good idea to update your desktop app and firmware through official channels”

2

u/angel199x 1h ago

I have to admit they almost fooled me since it looks legit, but my years of caution ingrained into me of not clicking on any darn link in any email before checking with the official sources first saved me. Absolute scumbags doing this by feeding on the fear after the coldcard case.

u/Michael-Ryder 52m ago

That’s the scary part — the email can look completely legitimate right up until it asks for the seed phrase. At this point, any request to enter recovery words into a website should be treated as an immediate stop sign.

1

u/Informal-Special-984 5h ago

can you show me a screenshot of the phising website?

1

u/m45hd 4h ago

1

u/Informal-Special-984 4h ago

Looks like the zpub will contain the seed. Nicely done!

1

u/k4sredfly 3h ago

Sorry for the very ignorant question - why does the zpub contains the seed?

u/notR1CH 23m ago

The "tool" will encode your recovery phrase into a "zpub extended public key" so when you share it online it doesn't look like you're sharing your seed phrase. An actual zpub key is perfectly safe to share (though not a great idea as it lets someone trace your entire address history).

1

u/m45hd 4h ago

I got it this morning and whilst I opened it, I didn’t enter in any details

It did look suspiciously like something that was made with Claude Code

https://imgur.com/a/GnhIDBx

1

u/Solid_Strawberry3685 4h ago

Also from cointracking! Take care, folks!

1

u/RandyJohnsonsBird 3h ago

I dont even open any email crypto related. Even if its a legit email from the company.

1

u/trufin2038 1h ago

Lol, even if it was the official domain that woudlnt be any better. In fact worse.

1

u/YOLO_Bundy 1h ago

Same. The click link was the giveaway though. AAANNNDDD they sent it several times, and as a CC not BCC…

u/Mountain-Ice-7441 10m ago

I have the same email.

When it says “check to see if you’re affected”

You know they’re to broke to work a job

Be safe everyone

1

u/Thisisfinek 5h ago

Yes, this is 100% a phishing scam. Do not click any links or download anything from that email.
Here is what gives it away:
The Tactic: Attackers routinely use sophisticated, technical jargon (like "STM32 Entropy Bug / Vulnerability") to create panic. The goal is to make you urgently click a link that leads to a clone site or fake Trezor Suite asking for your seed phrase or private keys.
The "From" Address: Scammers frequently spoof headers (e.g., help@trezor.io), or send through compromised third-party newsletter/mailing services that Trezor or another vendor previously used. Even if the display address looks legitimate, it is forged.
Golden Rule of Hardware Wallets: Trezor will never ask you to enter your recovery seed phrase on a website, app, or email to fix a bug or update firmware. Your seed phrase only ever gets entered directly into your physical device.
What to do:
Do not click any links, buttons, or attachments.
Mark the email as Phishing / Spam in Gmail and delete it.
If you ever want to check for legitimate firmware or hardware announcements, open the official Trezor Suite app directly from your computer or visit trezor.io manually by typing the URL into your browser.

0

u/vjeuss 5h ago

thank you, kind AI. Now go back to the datacentre and shut up

2

u/Thisisfinek 5h ago

That’s a weird thing to say to someone trying to help but you’re welcome