Community Trust ScoreVerified
Hardware wallet users woke up on September 9 to a nasty surprise. Both Trezor and BitBox fired off urgent alerts that day, warning their customers about phishing emails circulating under the companies’ own names — the result of a breach at their third-party email providers.
The attack wasn’t subtle. Trezor flagged a specific phishing message with the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” Technical-sounding, official-looking, and completely fake. The company was clear: that email did not come from them. Don’t click anything in it. Don’t follow any instructions. The breach, Trezor said, hit their third-party email provider — not their own internal systems — and the wallets themselves stayed secure throughout. Still, the damage to user trust is real. When a phishing email lands in your inbox looking like it came straight from your hardware wallet company, most people aren’t going to pause and check the headers.
How the Phishing Emails Got Through
BitBox put out its own warning the same day. Their newsletter provider was probably compromised, per the company’s update. BitBox moved fast — it contacted the provider directly, alerted all newsletter subscribers, and reported the malicious domains being used to host the phishing links. By the time they pushed their update out, many of those links had reportedly been taken down already. That’s a reasonably quick turnaround, but “reportedly” is doing some work there. No one has confirmed exactly how many links were neutralized or whether any remained active.
Trezor also took down at least one malicious domain tied to the campaign. They’re still digging into how attackers managed to access their legitimate email domain in the first place. That part’s unclear.
What’s not unclear: both companies share a concern that multiple Bitcoin-related businesses may have used the same newsletter provider. If that’s true, the blast radius here could be wider than just two companies. BitBox didn’t name any other affected firms, and no specifics have come out on that front. But the possibility sits there, uncomfortable.
What Users Should Actually Do
The guidance from both companies is pretty consistent. Ignore the phishing emails entirely. Don’t click links. Don’t download anything. And under no circumstances share your wallet recovery seed with anyone — not through an email prompt, not through a website that looks legitimate, not at all. Recovery seeds are basically the master key to your funds. If an attacker gets one, they don’t need your hardware wallet. They don’t need your PIN. They can drain everything from anywhere.
Trezor was specific on one more point: only download Trezor Suite from the official website. Phishing campaigns often push fake software downloads that look convincing enough to fool people who aren’t paying close attention. It’s a well-worn playbook in crypto attacks — get someone to install a malicious app, and the hardware wallet’s security model basically collapses.
Both companies are telling users to verify anything suspicious through official channels before acting on it. That’s good advice, though it’s worth noting that the phishing emails in this case were convincing enough to warrant a same-day emergency alert from two separate companies. So “just check if it’s real” is easier said than done when the fake looks that good.
Phishing attacks on hardware wallet users aren’t new. The crypto space has seen waves of them, often tied to data leaks at third-party service providers — mailing list vendors, newsletter platforms, customer support tools. The Ledger data breach back in 2020 became a textbook case: customer contact information leaked, and phishing attempts followed for months afterward. The pattern here feels similar. A shared service provider gets hit, and the attackers use the stolen email lists to run impersonation campaigns against users who have every reason to trust a message that appears to come from their wallet brand.
Investigations Still Open
Neither Trezor nor BitBox has disclosed the full scope of the breach. Who carried it out, exactly how they got in, how many email addresses were exposed — none of that has been confirmed publicly yet. Investigations are ongoing, both companies said. They’re monitoring closely. Standard language, and probably accurate, but it doesn’t tell users much about whether their contact information is now floating around somewhere it shouldn’t be.
The absence of specifics is frustrating but not unusual. Companies rarely put out full breach details while the investigation is still live. Doing so can tip off attackers or complicate coordination with law enforcement.
BitBox has been in contact with its newsletter provider. Trezor is actively working to understand how its email domain was accessed. Both firms have made clear they’re treating it seriously.
Users should keep an eye on official Trezor and BitBox channels for further updates. And if a security alert lands in your inbox claiming your hardware wallet has a critical vulnerability — especially one with a specific-sounding technical name — treat it as suspicious until you’ve confirmed it’s real through the company’s actual website or verified social accounts.
The malicious domains, at least many of them, are reportedly down.
Frequently Asked Questions
What was the fake Trezor phishing email about?
The phishing email used the subject line “Critical Security Alert: STM32 Entropy Vulnerability” to impersonate Trezor, but Trezor confirmed it did not send the email and warned users not to click any links in it.
Were the hardware wallets themselves compromised in the breach?
No — Trezor said the breach affected their third-party email provider, not their own systems, and assured users that the wallets remained secure.
Why It Matters
This phishing wave highlights the ongoing vulnerabilities within the cryptocurrency ecosystem, particularly concerning hardware wallets, which are often considered secure storage solutions for digital assets. The incident underscores the importance of robust cybersecurity measures, not only for wallet providers but also for users who must remain vigilant against increasingly sophisticated attacks. As trust in hardware wallets is essential for their adoption, breaches like this can erode confidence in the security of cryptocurrency storage solutions, potentially impacting user behavior and market dynamics.





