Trezor and BitBox warn users to be wary of phishing emails disguised as emergency security notices
Hardware wallet makers Trezor and BitBox recently issued a warning to remind users to pay attention to phishing emails disguised as emergency security notices. These attacks are suspected to involve breaches of third-party email services.
Trezor: Third-party mail provider compromised, STM32 vulnerability is a fake
Trezor warns users not to click on a link in a fraudulent email claiming an "STM32 entropy vulnerability" because its email provider was compromised. The company said on Wednesday that its email provider had been compromised and reminded users not to interact with fraudulent messages titled "Critical Security Alert: STM32 Entropy Vulnerability." Trezor tells recipients not to click on any links in the email.
Our third-party email provider has been compromised. Please note that the email titled 'Critical Security Alert: STM32 Entropy Vulnerability' did not come from us, it was a phishing attempt. Do not click on any links.
We have taken down the domain name and are investigating…
Trezor refuted the message and confirmed it was a phishing attempt. The company pointed out that the affected third-party email providers had been compromised, and its warning focused on preventing recipients from clicking on links contained in emails.
BitBox: Communication providers may be damaged, several Bitcoin enterprises affected
On the same day, BitBox issued a similar warning because users received phishing emails posing as the company. A preliminary review found that its newsletter provider was likely to have been compromised, and that several Bitcoin companies appear to have been targeted by sharing the same provider.
There is currently a phishing email impersonating us that is circulating. Do not follow the instructions in the email! We are investigating.
BitBox said that preliminary investigations revealed that its newsletter provider may have been compromised, and that several other Bitcoin companies appear to have used the same newsletter provider and been targeted. BitBox continues to investigate the incident while issuing warnings to subscribers.
Review of recent hardware wallet security incidents
This phishing warning follows recent hardware wallet security incidents. These include the ShipMonk data breach, which exposed the personal information of more than 80,000 Trezor customers. In addition, BitBox fixed two serious firmware vulnerabilities in August, but reported no known exploits or theft of user funds.
Earlier this year, another hardware wallet maker was indeed affected by a real-life vulnerability related to entropy. The AColdcard firmware flaw disclosed in July involved weak random number generation, which could put wallet mnemonics at risk. The problem stems from a build configuration error that caused the affected devices to use software pseudo-random number generators instead of the expected hardware random number generators. This vulnerability affects Coldcard Mk3 firmware since March 2021. Attackers later used this vulnerability to identify wallets created using fragile mnemonics. An attack on July 31 initially transferred 594 BTC worth approximately $38 million from approximately 500 addresses, and subsequent analysis linked more addresses and bitcoins to the vulnerability.
BitBox stated in July that its devices were not affected by the random number generation vulnerability.
Hardware wallet phishing attacks come in a variety of forms
Attacks faced by hardware wallet users do not necessarily require direct intrusion into the device itself. Certain activities turn to rely on impersonating wallet manufacturers to trick users into leaking recovery information.
- Physical letter fraud: In February, attackers sent physical letters posing as Trezor and Ledger, instructing recipients to scan QR codes for so-called identity verification or transaction checking. These official-looking letters and deadlines are designed to create a sense of urgency. The QR code directs users to malicious websites and requires a 12, 20, or 24-digit recovery mnemonic on the pretext of verifying wallet ownership. Anyone who gets a mnemonic can rebuild the associated wallet and control its funds. Trezor and Ledger emphasize that legitimate hardware wallet providers will never require users to enter, scan, upload, or share recovery mnemonics through websites or other external channels.
- Contact form abuse: In June 2025, an attacker abused Trezor's contact form, using the target user's email address to submit requests. Trezor's system then generated automated replies that appeared to come from its legitimate support infrastructure. This makes the phishing email appear more trustworthy because the recipient receives communications related to the company's support process. At the time, Trezor said its internal email infrastructure had not been compromised and warned users that it would never ask for a wallet backup and that recovery information should remain private and offline.
ShipMonk data breach affects more than 80,000 users
Trezor's latest phishing warning follows a separate disclosure of customer information by its transportation provider ShipMonk. On August 13, Trezor disclosed that unauthorized access to the ShipMonk system resulted in the exposure of 13,689 customer data. The initial disclosure covered 11,742 customers whose names, email addresses, phone numbers and shipping addresses were leaked; another 1,947 customers whose names, cities and email addresses were stolen. Trezor said its own systems had not been compromised and that its hardware wallet, private keys and recovery mnemons remained secure, but warned that exposed customer information could be used in more convincing phishing and impersonation attempts.
On September 4, Trezor expanded its disclosure of the ShipMonk incident after learning that about 67,000 other U.S. customers had been affected. These additional records belong to customers who placed orders between November 2019 and August 2021, including names, email addresses, telephone numbers, shipping addresses and order numbers. Coupled with the customers identified in August, the total number of people affected by the ShipMonk leak has exceeded 80,000. Trezor said it had previously received customer information that Assurances believed was removed from the ShipMonk system, but learned on September 2 that the records were still stored by the transportation provider.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC