Digital Wallet

Story: Trezor and BitBox Users Targeted by Phishing Scams After Email Provider Breach

By Sakamoto Nashi

1 / 15

How the Phishing Emails Got Through. BitBox put out its own warning the same day. Their newsletter provider was probably compromised,…

2 / 15

What Users Should Actually Do. The guidance from both companies is pretty consistent. Ignore the phishing emails entirely.

3 / 15

Investigations Still Open. Neither Trezor nor BitBox has disclosed the full scope of the breach.

4 / 15

Hardware wallet users woke up on September 9 to a nasty surprise. Both Trezor and BitBox fired off urgent alerts that day, warning their customers about phishing emails…

5 / 15

The attack wasn't subtle. Trezor flagged a specific phishing message with the subject line "Critical Security Alert: STM32 Entropy Vulnerability.

6 / 15

Trezor also took down at least one malicious domain tied to the campaign. They're still digging into how attackers managed to access their legitimate email domain in the first…

7 / 15

What's not unclear: both companies share a concern that multiple Bitcoin-related businesses may have used the same newsletter provider.

8 / 15

The guidance from both companies is pretty consistent. Ignore the phishing emails entirely. Don't click links. Don't download anything.

9 / 15

Trezor was specific on one more point: only download Trezor Suite from the official website.

10 / 15

See also: Trezor Users Targeted by Phishing Attack Using Legitimate Email Infrastructure

11 / 15

Both companies are telling users to verify anything suspicious through official channels before acting on it.

12 / 15

Phishing attacks on hardware wallet users aren't new. The crypto space has seen waves of them, often tied to data leaks at third-party service providers — mailing list vendors,…

13 / 15

Neither Trezor nor BitBox has disclosed the full scope of the breach. Who carried it out, exactly how they got in, how many email addresses were exposed — none of that has been…

14 / 15

The absence of specifics is frustrating but not unusual. Companies rarely put out full breach details while the investigation is still live.

15 / 15

See also: Brevo SSO Flaw Hits 347,000 Trezor Users with Phishing Attack

The Currency Analytics

Want the full story?