Back Altcoinbuzz Trezor, BitBox Warn of Phishing Emails After Email Provider Breach
Hardware wallet makers Trezor and BitBox have warned users a coordinated phishing campaign in which fraudulent security alerts were sent through legitimate looking email infrastructure.
The campaign emerged on September 9, with attackers impersonating Trezor and BitBox and using claims serious hardware wallet vulnerabilities to pressure recipients into taking action. Trezor confirmed that its third-party email provider had been breached , allowing the attackers to send a fake security alert through legitimate Trezor mailing infrastructure.
The incident is particularly concerning because the emails did not simply rely on lookalike domains. Security researchers found evidence that at least some messages were sent through infrastructure associated with the companies' genuine mailing systems, making them considerably harder for ordinary users to distinguish from legitimate communications.
Trezor Confirms Third-Party Email Provider Breach
Trezor warned users on September 9 that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” was fraudulent.
Trezor said its third-party email provider had been breached and instructed users not to click links in the message. The company also said it had taken down the domain involved and was investigating how attackers gained access to its legitimate email infrastructure.
The fake email claimed that a critical hardware-level vulnerability involving STM32 microcontrollers could leave some Trezor devices generating weak wallet seeds. It then directed users to a page supposedly designed to determine whether their devices were affected.
The campaign was designed to exploit a legitimate security concern. Hardware wallet users are accustomed to treating firmware and cryptographic warnings seriously, making an urgent message wallet entropy particularly effective as a phishing lure.
BitBox Warns of a Similar Campaign
BitBox also warned its users fraudulent emails appearing to originate from the company.
The company said its preliminary investigation indicated that its provider was likely compromised and that multiple Bitcoin companies appeared to have been targeted through a shared provider.
The similarity between the campaigns has raised concerns that attackers may have compromised a common marketing or infrastructure rather than separately breaching each hardware-wallet company.
Independent analysis found shared technical indicators involving the mailing configurations of Trezor, BitBox and Shift Crypto, the company behind BitBox. However, the precise route of compromise remains under investigation.
BitBox's official security guidance also stresses that an official-looking email address does not make a request for wallet secrets legitimate. The company advises users to verify uncertain messages through its official support channels.
The Phishing Campaign Targets Wallet Secrets
The fake Trezor alert reportedly directed users toward a page where they could supposedly check whether their wallet was affected.
Some variants requested an xPub , or extended public key. An xPub cannot authorize transactions or directly spend funds, but it can reveal the addresses and balances associated with a wallet.
Other phishing variants targeting hardware-wallet users have gone further by requesting recovery phrases.
That is the critical line users should remember: a legitimate hardware wallet company should never require a recovery phrase to verify or secure a device online.
If a user enters a recovery phrase into a phishing website, the attacker can use it to recreate the wallet and potentially move its funds. Simply receiving a phishing email does not compromise a wallet, and clicking a link without entering sensitive information does not automatically mean the wallet's recovery phrase has been exposed.
Hardware Wallet Users Have Faced Several Recent Threats
The latest campaign follows a series of security incidents and disclosures affecting the hardware-wallet sector.
In August, Trezor users were also warned phishing attempts exploiting concerns surrounding vulnerabilities reported in competing hardware wallets. Around the same period, the Coldcard ecosystem suffered a major security incident involving weak random-number generation, resulting in more than $111 million in reported Bitcoin losses according to earlier industry coverage.
The incidents demonstrate why attackers can successfully combine genuine technical research with fraudulent claims. A real vulnerability affecting one wallet or component can provide enough technical credibility to make a completely fake warning another product appear believable.
Related: Crypto Hacks Surge in August as 50 Attacks Steal $136M
What Trezor and BitBox Users Should Do
Users who receive a security email should avoid clicking links inside the message, particularly when it creates urgency or asks them to verify wallet information.
Hardware-wallet recovery phrases should never be entered into websites, email forms or online verification pages. If a user has already entered a recovery phrase into a suspicious website, BitBox's guidance is to treat the wallet as compromised and move funds to a newly generated wallet.
Users who only received the email or opened the message without submitting sensitive information should not assume their wallet has been compromised.
The safest approach is to navigate directly to the manufacturer's official website or application rather than following links contained in an unsolicited security alert.
A Broader Warning for Crypto Security
The Trezor and BitBox incidents demonstrate an increasingly important problem in crypto security: compromising a service provider can sometimes be enough to bypass the trust users place in a legitimate brand .
An email can contain a genuine company address, pass standard authentication checks and still be malicious if an attacker has gained access to the infrastructure authorized to send those messages.
That makes traditional checks such as verifying the sender address less reliable on their own.
For hardware wallet users, the strongest defense remains keeping recovery phrases offline and treating any unexpected request to enter wallet credentials, seed words or other sensitive information online as a potential phishing attempt.
DOJ Restrains $52.8M in Crypto Tied to Chinese Scam Marketplace Xinbi
The DOJ and U.S. Treasury have targeted Xinbi Guarantee, restraining $52.8 million in crypto linked to the Chinese-language scam marketplace and disrupting its Telegram infrastructure.
Solana Widens Memecoin Volume Lead Over Robinhood to 67%
Solana captured 67% of all memecoin DEX trading volume on September 7, nearly three times Robinhood's 23% , while also taking the lead in x402 activity.
Bessent Urges Senate to Advance CLARITY Act Ahead of Sept. 15 Vote
Treasury Secretary Scott Bessent is urging the Senate to advance the CLARITY Act before the September 15 procedural vote, framing the legislation as a tool for crypto regulation, enforcement and national security.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
