Phishing attack underway targeting @BitBoxSwiss and @Trezor customers.
There is no entropy vulnerability; this is a malicious email from an attacker attempting to obtain your seed phrase.
The @BitBoxSwiss account has already issued a warning.
The @Trezor account will surely do so shortly.
If you have to give out an email when ordering a signing device, give a throwaway email
It's always the most advisable thing to do.
Here's the warning from Trezor: https://x.com/Trezor/status/2097786518110609620
https://twiiit.com/Trezor/status/2097786518110609620
He’s done it—great! Now, spread the word among the Stackers so no one falls prey to scammers... SN ALERT.
eek, those look well done.
That’s what phishing is about: they impersonate support to obtain your seed phrase using social engineering.
The phishing attack targeting BitBoxSwiss and Trezor customers is likely a spear-phishing campaign exploiting social engineering and technical vulnerabilities. Here’s a working solution:
bitboxswiss.com,trezor.io) and domain keys (DKIM, SPF, DMARC). Legitimate entities rarely use generic email providers (e.g., Gmail, Outlook) for critical alerts.bitboxswiss-support[.]com), it’s a phishing site. Use tools like VirusTotal or URLScan.io to analyze the link.bitboxswiss[.]support). Compare the domain with the official website’s WHOIS records.This approach combines forensic analysis, user education, and proactive security measures to mitigate the attack.
Useful reminder: this is social engineering for the seed, not an entropy bug in BitBox/Trezor.
Concrete checks before anyone panics:
@Kruw linked Trezor's warning; BitBoxSwiss already posted theirs. Mute/report the sender and do not engage.
The two screenshots are worth reading side by side. The BitBox one is titled
"Microcontroller Entropy Vulnerability", the Trezor one "STM32 Entropy Bug".
Same lie, rewritten per vendor with the correct chip named. That isn't spray and
pray, somebody segmented a customer list.
Second detail in both shots: Gmail is rendering an Unsubscribe chip. That only
shows up when the sender set a List-Unsubscribe header, which means this went
out through bulk mail tooling. No hardware wallet vendor pushes a critical
security advisory through a marketing blast.
The rule that survives every variant of this one: a genuine entropy bug is fixed
by generating a new wallet on patched firmware and moving your coins. That never
requires telling anyone your old words. Any remediation flow that asks for your
recovery phrase is the attack, not the fix.