Newsroom

Trezor and BitBox Warn of Phishing Emails After Third-Party Email Provider Breaches

10 September, 2026   /   News   /  AI   /   Tags:  trezor, bitbox, email, emails, phishing

Trezor and BitBox Warn of Phishing Emails After Third-Party Email Provider Breaches

Hardware wallet makers alert users to fraudulent security notices sent via compromised email services, following recent data exposures

Hardware wallet companies Trezor and BitBox issued urgent warnings on September 9, 2026, after attackers exploited breaches at third-party email providers to distribute phishing messages. The campaigns used legitimate-looking domains and addresses to urge recipients to respond to fabricated hardware security flaws.

Trezor Confirms Email Provider Breach

Trezor stated that attackers breached its third-party email provider and used the access to send messages titled “Critical Security Alert: STM32 Entropy Vulnerability.” The emails appeared to originate from official addresses associated with the company, including [email protected], and leveraged subdomains under its mailing infrastructure.

The fraudulent messages claimed that engineers had identified a critical hardware-level defect in STM32 microcontrollers found in Trezor devices. According to the emails, the issue allegedly reduced the randomness, or entropy, used to generate recovery phrases and affected an estimated one in four devices. Recipients were directed to a link, presented as a verification or update page, to check whether their hardware was impacted.

Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
Trezor

Trezor reported that it had taken down the domain involved in the campaign and was investigating how the attackers obtained access to its legitimate domain. The company stressed that wallets, private keys, and recovery backups were never exposed in the incident.

The timing of the phishing attempt followed heightened attention to entropy-related risks in the hardware wallet sector. The messages referenced concerns similar to those raised by a recent vulnerability affecting another manufacturer’s devices.

BitBox Reports Parallel Campaign

On the same day, Swiss hardware wallet maker BitBox warned that phishing emails impersonating the company had been sent to its newsletter subscribers. The firm’s preliminary review indicated that its newsletter provider had likely been compromised.

BitBox noted that multiple other Bitcoin companies appeared to have been targeted through a shared provider. The company contacted the provider, reported the phishing domains, and stated that most of the malicious links had already been taken down. It continued to investigate the situation and advised subscribers not to follow any instructions in the unexpected messages.

Security researchers observed that the emails targeting both Trezor and BitBox users did not appear to be simple spoofs. Casa Chief Security Officer Jameson Lopp stated that threat actors may have compromised the email provider or providers used by the two firms. Casa co-founder and CEO Nick Neuman similarly pointed to a likely compromise of a marketing email provider shared across companies.

Context of Recent Vendor Incidents

The email provider breach marked the third vendor-related security issue for Trezor in roughly four weeks. In August, a breach at shipping partner ShipMonk exposed personal information belonging to more than 80,000 customers. Initial reports indicated nearly 14,000 affected individuals; a subsequent update raised the total by an additional 67,000 U.S. customers. The leaked data included names, phone numbers, email addresses, and shipping addresses, increasing the risk of targeted follow-on scams such as calls and physical letters.

Earlier incidents in the broader sector, including a 2024 support portal breach that prompted Trezor to warn 66,000 users, have similarly focused attention on the security of third-party partners that handle customer contact information rather than the hardware devices themselves.

Guidance for Users

Both companies and independent security voices advised recipients to treat unexpected messages with extreme caution. Users should avoid clicking any links in emails citing STM32 issues or entropy problems, refrain from entering recovery phrases or device passcodes on any website, and verify all official communications through the companies’ verified websites or social media accounts.

Anyone who interacted with a linked page and entered sensitive backup information was advised to move funds to a newly generated wallet. Contact details obtained from prior data exposures, combined with messages that successfully pass standard email authentication checks, reduce the usual signals that help identify phishing attempts.

Trezor and BitBox continue to monitor the situation and have directed users to their official channels for further updates.

Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.