AI Weekly Malaysia

Back to items Summaries

Trezor, BitBox users targeted in newsletter phishing spree

ID
23128
Status
summarized
Published
10 Sep 2026, 7:30 PM
Fetched
10 Sep 2026, 8:10 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/5295496
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
3.5
Created
10 Sep 2026, 8:11 PM
Tags
Audience
developerssaas_founders

What happened

Attackers compromised a third-party email service provider used by crypto hardware wallet makers Trezor and BitBox to send phishing emails through legitimate mailing channels. The phishing emails, titled 'Critical Security Alert: STM32 Entropy Vulnerability' (Trezor) and 'Critical Security Alert: Microcontroller Entropy Bug Identified' (BitBox), claim a hardware defect exposes wallet seeds to brute-force attacks and ask recipients to share their wallet backups. Because the emails come through the breached legitimate provider, they pass authentication checks and appear sent from mailing@trezor.io.

Why it matters

If you run a SaaS or any product that sends transactional or marketing email through a third-party ESP, this is a concrete reminder that a compromise of that vendor means attackers can send authenticated phishing from your domain. The practical takeaway: review whether your ESP supports scoped API keys, sender authentication isolation, and incident response playbooks—because Trezor and BitBox had no way to stop authenticated emails going out from their own addresses. That said, this is crypto-specific and not actionable for most builders unless they ship email infrastructure.

Discussion angle

Third-party email provider as a single point of failure: what would you do if your ESP was breached and attackers could send authenticated emails from your domain? Worth a quick discussion on ESP access controls and incident response.

Top