EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Trezor, BitBox warn users: phishing emails target wallet holders

2026-09-10 16:11:08
Bookmark

Trezor and BitBox warn users to be wary of phishing emails disguised as emergency security notices

Hardware wallet makers Trezor and BitBox recently issued a warning to remind users to pay attention to phishing emails disguised as emergency security notices. These attacks are suspected to involve breaches of third-party email services.

Trezor: Third-party mail provider compromised, STM32 vulnerability is a fake

Trezor warns users not to click on a link in a fraudulent email claiming an "STM32 entropy vulnerability" because its email provider was compromised. The company said on Wednesday that its email provider had been compromised and reminded users not to interact with fraudulent messages titled "Critical Security Alert: STM32 Entropy Vulnerability." Trezor tells recipients not to click on any links in the email.

Our third-party email provider has been compromised. Please note that the email titled 'Critical Security Alert: STM32 Entropy Vulnerability' did not come from us, it was a phishing attempt. Do not click on any links.
We have taken down the domain name and are investigating…

Trezor refuted the message and confirmed it was a phishing attempt. The company pointed out that the affected third-party email providers had been compromised, and its warning focused on preventing recipients from clicking on links contained in emails.

BitBox: Communication providers may be damaged, several Bitcoin enterprises affected

On the same day, BitBox issued a similar warning because users received phishing emails posing as the company. A preliminary review found that its newsletter provider was likely to have been compromised, and that several Bitcoin companies appear to have been targeted by sharing the same provider.

There is currently a phishing email impersonating us that is circulating. Do not follow the instructions in the email! We are investigating.

BitBox said that preliminary investigations revealed that its newsletter provider may have been compromised, and that several other Bitcoin companies appear to have used the same newsletter provider and been targeted. BitBox continues to investigate the incident while issuing warnings to subscribers.

Review of recent hardware wallet security incidents

This phishing warning follows recent hardware wallet security incidents. These include the ShipMonk data breach, which exposed the personal information of more than 80,000 Trezor customers. In addition, BitBox fixed two serious firmware vulnerabilities in August, but reported no known exploits or theft of user funds.

Earlier this year, another hardware wallet maker was indeed affected by a real-life vulnerability related to entropy. The AColdcard firmware flaw disclosed in July involved weak random number generation, which could put wallet mnemonics at risk. The problem stems from a build configuration error that caused the affected devices to use software pseudo-random number generators instead of the expected hardware random number generators. This vulnerability affects Coldcard Mk3 firmware since March 2021. Attackers later used this vulnerability to identify wallets created using fragile mnemonics. An attack on July 31 initially transferred 594 BTC worth approximately $38 million from approximately 500 addresses, and subsequent analysis linked more addresses and bitcoins to the vulnerability.

BitBox stated in July that its devices were not affected by the random number generation vulnerability.

Hardware wallet phishing attacks come in a variety of forms

Attacks faced by hardware wallet users do not necessarily require direct intrusion into the device itself. Certain activities turn to rely on impersonating wallet manufacturers to trick users into leaking recovery information.

  • Physical letter fraud: In February, attackers sent physical letters posing as Trezor and Ledger, instructing recipients to scan QR codes for so-called identity verification or transaction checking. These official-looking letters and deadlines are designed to create a sense of urgency. The QR code directs users to malicious websites and requires a 12, 20, or 24-digit recovery mnemonic on the pretext of verifying wallet ownership. Anyone who gets a mnemonic can rebuild the associated wallet and control its funds. Trezor and Ledger emphasize that legitimate hardware wallet providers will never require users to enter, scan, upload, or share recovery mnemonics through websites or other external channels.
  • Contact form abuse: In June 2025, an attacker abused Trezor's contact form, using the target user's email address to submit requests. Trezor's system then generated automated replies that appeared to come from its legitimate support infrastructure. This makes the phishing email appear more trustworthy because the recipient receives communications related to the company's support process. At the time, Trezor said its internal email infrastructure had not been compromised and warned users that it would never ask for a wallet backup and that recovery information should remain private and offline.

ShipMonk data breach affects more than 80,000 users

Trezor's latest phishing warning follows a separate disclosure of customer information by its transportation provider ShipMonk. On August 13, Trezor disclosed that unauthorized access to the ShipMonk system resulted in the exposure of 13,689 customer data. The initial disclosure covered 11,742 customers whose names, email addresses, phone numbers and shipping addresses were leaked; another 1,947 customers whose names, cities and email addresses were stolen. Trezor said its own systems had not been compromised and that its hardware wallet, private keys and recovery mnemons remained secure, but warned that exposed customer information could be used in more convincing phishing and impersonation attempts.

On September 4, Trezor expanded its disclosure of the ShipMonk incident after learning that about 67,000 other U.S. customers had been affected. These additional records belong to customers who placed orders between November 2019 and August 2021, including names, email addresses, telephone numbers, shipping addresses and order numbers. Coupled with the customers identified in August, the total number of people affected by the ShipMonk leak has exceeded 80,000. Trezor said it had previously received customer information that Assurances believed was removed from the ShipMonk system, but learned on September 2 that the records were still stored by the transportation provider.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP