Newsroom
10 September, 2026 / News / AI / Tags: trezor, bitbox, email, emails, phishing

Hardware wallet makers alert users to fraudulent security notices sent via compromised email services, following recent data exposures
Hardware wallet companies Trezor and BitBox issued urgent warnings on September 9, 2026, after attackers exploited breaches at third-party email providers to distribute phishing messages. The campaigns used legitimate-looking domains and addresses to urge recipients to respond to fabricated hardware security flaws.
Trezor stated that attackers breached its third-party email provider and used the access to send messages titled “Critical Security Alert: STM32 Entropy Vulnerability.” The emails appeared to originate from official addresses associated with the company, including [email protected], and leveraged subdomains under its mailing infrastructure.
The fraudulent messages claimed that engineers had identified a critical hardware-level defect in STM32 microcontrollers found in Trezor devices. According to the emails, the issue allegedly reduced the randomness, or entropy, used to generate recovery phrases and affected an estimated one in four devices. Recipients were directed to a link, presented as a verification or update page, to check whether their hardware was impacted.
Trezor reported that it had taken down the domain involved in the campaign and was investigating how the attackers obtained access to its legitimate domain. The company stressed that wallets, private keys, and recovery backups were never exposed in the incident.
The timing of the phishing attempt followed heightened attention to entropy-related risks in the hardware wallet sector. The messages referenced concerns similar to those raised by a recent vulnerability affecting another manufacturer’s devices.
On the same day, Swiss hardware wallet maker BitBox warned that phishing emails impersonating the company had been sent to its newsletter subscribers. The firm’s preliminary review indicated that its newsletter provider had likely been compromised.
BitBox noted that multiple other Bitcoin companies appeared to have been targeted through a shared provider. The company contacted the provider, reported the phishing domains, and stated that most of the malicious links had already been taken down. It continued to investigate the situation and advised subscribers not to follow any instructions in the unexpected messages.
Security researchers observed that the emails targeting both Trezor and BitBox users did not appear to be simple spoofs. Casa Chief Security Officer Jameson Lopp stated that threat actors may have compromised the email provider or providers used by the two firms. Casa co-founder and CEO Nick Neuman similarly pointed to a likely compromise of a marketing email provider shared across companies.
The email provider breach marked the third vendor-related security issue for Trezor in roughly four weeks. In August, a breach at shipping partner ShipMonk exposed personal information belonging to more than 80,000 customers. Initial reports indicated nearly 14,000 affected individuals; a subsequent update raised the total by an additional 67,000 U.S. customers. The leaked data included names, phone numbers, email addresses, and shipping addresses, increasing the risk of targeted follow-on scams such as calls and physical letters.
Earlier incidents in the broader sector, including a 2024 support portal breach that prompted Trezor to warn 66,000 users, have similarly focused attention on the security of third-party partners that handle customer contact information rather than the hardware devices themselves.
Both companies and independent security voices advised recipients to treat unexpected messages with extreme caution. Users should avoid clicking any links in emails citing STM32 issues or entropy problems, refrain from entering recovery phrases or device passcodes on any website, and verify all official communications through the companies’ verified websites or social media accounts.
Anyone who interacted with a linked page and entered sensitive backup information was advised to move funds to a newly generated wallet. Contact details obtained from prior data exposures, combined with messages that successfully pass standard email authentication checks, reduce the usual signals that help identify phishing attempts.
Trezor and BitBox continue to monitor the situation and have directed users to their official channels for further updates.









