Trezor, BitBox warn users after phishing emails target wallet holders
Hardware wallet makers Trezor and BitBox have warned users about phishing emails disguised as urgent security notices after suspected compromises involving third party email services.
- Trezor warned users not to click links in a fraudulent email claiming an STM32 entropy vulnerability after its email provider was breached.
- BitBox said its newsletter provider was likely compromised, with several Bitcoin companies appearing to have been targeted through the same provider.
- The phishing warnings follow recent hardware wallet security incidents, including a ShipMonk breach that exposed data belonging to more than 80,000 Trezor customers.
- BitBox patched two severe firmware vulnerabilities in August but reported no known exploitation or stolen user funds.
Trezor said on Wednesday that its email provider had been breached and warned users not to interact with a fraudulent message titled “Critical Security Alert: STM32 Entropy Vulnerability.” The company told recipients not to click any links in the email.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
— Trezor (@Trezor) September 9, 2026
We have taken down the domain, and we are investigating…
BitBox issued a similar warning the same day after users received a phishing email impersonating the company. Its preliminary review found that its newsletter provider was likely compromised, with several Bitcoin companies appearing to have been targeted through a provider they shared.
There is currently a phishing email going around that's pretending to come from us.
— BitBox (@BitBoxSwiss) September 9, 2026
Please do not follow the instructions in the email!
We are currently investigating. https://t.co/vKK4VxYPm3
Trezor phishing email claims entropy vulnerability
The fraudulent Trezor email presented the supposed STM32 entropy vulnerability as a security problem requiring users to take action.
Trezor rejected the message and confirmed that it was a phishing attempt. The company said the affected third party email provider had been breached, while its warning focused on preventing recipients from following links contained in the message.
The phishing campaign comes after a real entropy related vulnerability affected another hardware wallet maker earlier this year. A Coldcard firmware flaw disclosed in July involved weak random number generation that could result in vulnerable wallet seeds.
The Coldcard issue stemmed from a build configuration error that caused affected devices to use a software pseudorandom number generator instead of the intended hardware random number generator. The vulnerability affected Coldcard Mk3 firmware dating back to March 2021.
Attackers later exploited the weakness to identify wallets created with vulnerable seeds. An attack on July 31 initially moved 594 BTC worth approximately $38 million from around 500 addresses, with later analysis connecting more addresses and Bitcoin to the same vulnerability.
As crypto.news previously reported, the Coldcard security incident prompted Kraken Chief Security Officer Nick Percoco to call for independent audits of hardware wallet seed generation. Coinkite released firmware fixes, but wallets created using vulnerable seeds still required users to generate new seed phrases and move their Bitcoin.
BitBox said in July that its devices were not affected by the random number generation vulnerability.
BitBox points to newsletter provider compromise
BitBox said its preliminary investigation indicated that its newsletter provider was likely compromised after phishing emails impersonating the hardware wallet company reached users.
The company found that several other Bitcoin businesses had been targeted and appeared to use the same newsletter provider. BitBox warned subscribers about the phishing attempt while continuing to investigate the incident.
The phishing campaign followed a separate BitBox security disclosure in August, when the company patched two firmware flaws affecting its hardware wallets.
One of the vulnerabilities could have allowed malicious firmware to be installed under certain conditions. The second involved Bitcoin address handling and could have affected how addresses were verified.
BitBox said there was no known exploitation of either vulnerability and no user funds were reported stolen. Updated firmware was released to address both issues.
Hardware wallet users have faced attacks that do not require compromising the devices themselves. Some campaigns instead rely on impersonating wallet manufacturers and persuading users to disclose recovery information.
In February, attackers sent physical letters impersonating Trezor and Ledger and directed recipients to scan QR codes for supposed authentication or transaction checks.
The hardware wallet phishing campaign used official looking letters and deadlines to create urgency. The QR codes directed users to malicious websites that requested 12, 20 or 24 word recovery phrases under the pretense of verifying wallet ownership.
Anyone who obtains a recovery phrase can recreate the associated wallet and control its funds. Trezor and Ledger said legitimate hardware wallet providers do not ask users to enter, scan, upload or share recovery phrases through websites or other external channels.
Trezor customer data breach affected more than 80,000 users
Trezor’s latest phishing warning follows separate disclosures involving customer information held by its shipping provider ShipMonk.
On Aug. 13, Trezor disclosed that unauthorized access to ShipMonk systems had exposed data belonging to 13,689 customers.
The initial disclosure covered 11,742 customers whose names, email addresses, phone numbers and shipping addresses were exposed. Another 1,947 customers had their names, cities and email addresses compromised.
Trezor said its own systems were not breached and its hardware wallets, private keys and recovery phrases remained secure. The company warned that the exposed customer information could be used for more convincing phishing and impersonation attempts.
The ShipMonk incident was mentioned in previous coverage of the BitBox firmware vulnerabilities, alongside another customer data exposure involving hardware wallet maker SafePal. Neither incident compromised the companies’ hardware wallets or recovery phrases.
Trezor expanded its ShipMonk disclosure on Sept. 4 after learning that another approximately 67,000 U.S. customers were affected.
The additional records belonged to customers who placed orders between November 2019 and August 2021 and included names, email addresses, phone numbers, shipping addresses and order numbers.
Combined with the customers identified in August, the expanded disclosure brought the number affected by the ShipMonk breach to more than 80,000.
Trezor said it had previously received assurances that the older customer information had been deleted from ShipMonk’s systems. The company learned on Sept. 2 that the records had remained stored by the shipping provider.
Hardware wallet phishing has taken several forms
Trezor has dealt with phishing attempts through other communication channels before the latest email provider incident.
In June 2025, attackers abused the company’s contact form by submitting requests using targeted users’ email addresses. Trezor’s system then generated automated responses that appeared to come from its legitimate support infrastructure.
The Trezor contact form attack allowed the phishing messages to appear more credible because recipients received communications associated with the company’s support process.
Trezor said at the time that its internal email infrastructure had not been breached. The company warned users that it would never request their wallet backup and said recovery information should remain private and offline.
The phishing attempts targeting Trezor and BitBox this week instead led both companies to point to third party email services. BitBox said several Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor confirmed that its email provider had been breached.