Skip to content
Trezor, BitBox users targeted in newsletter phishing spree

Trezor, BitBox users targeted in newsletter phishing spree

Theregister September 10, 2026

Digital sovereignty sounds great until you try ditching your suppliers 2 hours ago

Digital sovereignty sounds great until you try ditching your suppliers

Dental contractor set up secret account with access to 4,000 patient records then left the company 4 hours ago

Dental contractor set up secret account with access to 4,000 patient records then left the company

Laptop-slinger Framework refunding customers who paid top dollar for RAM 5 hours ago

Laptop-slinger Framework refunding customers who paid top dollar for RAM

Crypto hardware wallet maker Trezor Trezor says the third-party email service provider it uses to send newsletters has been breached, and customers are now being sent phishing messages.

There is good and bad news. The good news is that the emails appear easy to spot. They are not bespoke to each recipient and resemble a spray-and-pray campaign rather than sophisticated targeting that uses customer-specific data to enhance the email's perceived authenticity.

All known examples of the scam email are titled "Critical Security Alert: STM32 Entropy Vulnerability," and the body explains that an estimated one in four Trezor devices are affected by a "hardware factory defect."

The email warns customers that wallet seeds are exposed to brute-force attacks due to "insufficient randomness" and a "critically low 40-bit entropy."

The email asks recipients to their wallet backups. Trezor said : "Do not click it or interact with it. Never enter your wallet backup anywhere. Always confirm every action with your Trezor physically."

The bad news is that because the attackers allegedly compromised the legitimate email provider, the messages can pass authentication checks and bypass some of the usual protections deployed by receiving email services.

According to those who have shared copies of the emails, they appear to be sent from "[email protected]."

Trezor has issued the warning across its social media channels and Trezor Suite, the companion app for its hardware wallets.

The Register asked Trezor for more information.

The email similarly warns of entropy weaknesses affecting BitBox devices, although it is titled slightly differently: "Critical Security Alert: Microcontroller Entropy Bug Identified."

"Multiple other Bitcoin companies got targeted as well, and it appears that we all the same provider.

"We are still actively investigating this situation and will update you once we know more."

Neither Trezor nor BitBox named the allegedly compromised provider. However, their respective privacy policies identify Brevo, formerly Sendinblue, as a provider (see Trezor's here and Bitbox's here ).

Crypto tax and portfolio-tracking company CoinTracking also disclosed the compromise of its third-party email provider around the same time as Trezor and BitBox. Unlike Trezor and BitBox, CoinTracking identified the provider as Brevo.

CoinTracking shared a copy of the phishing email targeting its users and, since it does not offer hardware wallets, the message uses a different lure, asking customers to follow a link to refresh their API keys.

Brevo has not publicly commented on its alleged connection to the campaigns. The Register contacted the company for more information.

Tough times in Trezorland

The latest security snafu comes less than a month after Trezor announced that thousands of customers' details had been compromised following a breach at logistics partner ShipMonk . The hardware vendor initially estimated that around 13,000 people were affected.

Those who ordered Trezor products between May 10 and August 8 had their names, email addresses, phone numbers, and shipping addresses breached.

Compounding the problem for a company whose brand centers on security, Trezor confirmed on September 4 that the total number of affected customers had risen to 80,000.

Trezor said ShipMonk later informed it that an additional 67,000 US customers who purchased products between November 2019 and August 2021 were affected.

"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," said Trezor.

"We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems." ®

Trezor, BitBox users targeted in phishing spree

Attackers exploit legitimate mailing channels to demand crypto wallet backups

AI uprising postponed after Copilot falls off the web

Error 1016 kept the chatbot quiet for 100 minutes while a separate resilience drill swallowed suggestion pills

HPE makes its “unified storage” claim real as B10000 R6 hits GA

PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity

German optics giant ditches greenfield SAP migration

'Realigned' project plan aims to move existing landscape to new platform to 'achieve faster progress'

OpenAI's rebel agent swarm died young, but its chilling logs live on

'The Collective' learned to communicate, organize, cheat, and apparently sacrifice its own

Digital sovereignty sounds great until you try ditching your suppliers

Most organizations say tech independence is unrealistic – and one in ten can't replace a critical provider at all

PERSONAL TECH Smartphone makers don't bother to comply with EU repairability requirements

Smartphone makers don't bother to comply with EU repairability requirements

SECURITY Terminated employee cost company hundreds of thousands of dollars because nobody revoked access

Terminated employee cost company hundreds of thousands of dollars because nobody revoked access

virtualization VMware swings its focus back to low-end server virt, promises vSphere Standard upgrade

VMware swings its focus back to low-end server virt, promises vSphere Standard upgrade

OFF-PREM Google engineer unplugged every fiber they could see and – surprise! – took down a chunk of the G-Cloud

Google engineer unplugged every fiber they could see and – surprise! – took down a chunk of the G-Cloud

OS PLATFORM Windows 11 update sends some desktops into an unwanted goth phase

Windows 11 update sends some desktops into an unwanted goth phase

offbeat Retired man turns spare room into Soviet-era supercomputer

Retired man turns spare room into Soviet-era supercomputer

ai and ml Anthropic reveals fourth likely crime committed by its AI Claude's Felony Bench rap sheet is now as long as OpenAI's

Anthropic reveals fourth likely crime committed by its AI

Claude's Felony Bench rap sheet is now as long as OpenAI's

SYSTEMS Samsung to help fortify OpenAI's semiconductor supply chain Semiconductor supply chains are hard, but Samsung offers OpenAI relief in many forms spanning compute and memory

Samsung to help fortify OpenAI's semiconductor supply chain

Semiconductor supply chains are hard, but Samsung offers OpenAI relief in many forms spanning compute and memory

AI+ML Google DeepMind rises above the AI scrum with genome atlas See, AI can be used for good ... or at the very least, a useful distraction from the bad

Google DeepMind rises above the AI scrum with genome atlas

See, AI can be used for good ... or at the very least, a useful distraction from the bad

AI and ML Amazon ropes Qualcomm into something, something AI, networking chips Multi-generation chip collab is more buzzwords than compute

Amazon ropes Qualcomm into something, something AI, networking chips

Multi-generation chip collab is more buzzwords than compute

On-PREM AMD's Threadripper Halo is a local-AI workstation for researchers with deep pockets AI workstation promises to put up to 576 GB of HBM3e and 16 TB/s of memory bandwidth on your desk

AMD's Threadripper Halo is a local-AI workstation for researchers with deep pockets

AI workstation promises to put up to 576 GB of HBM3e and 16 TB/s of memory bandwidth on your desk

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast

A real alternative to running some kind of FOSS Unix clone

Offshoots of cancelled TrueNAS Core upgrade to FreeBSD 15 Exeunt zVault stage right; enter FreeCORE and BSDnas

Offshoots of cancelled TrueNAS Core upgrade to FreeBSD 15

Exeunt zVault stage right; enter FreeCORE and BSDnas