Trezor, BitBox Warn of Phishing After Third-Party Email Breach

Fake emails claimed a critical STM32 vulnerability affected Trezor hardware wallets.

Follow on Google News
Trezor, BitBox Warn of Phishing After Third-Party Email Breach
  • Trezor said attackers used a breached third-party email provider to send spoofed phishing messages.
  • Fake emails falsely claimed a critical STM32 vulnerability affected hardware wallets.
  • BitBox reported similar phishing attempts, while a Casa executive suggested a shared email provider may have been compromised.

Trezor, a hardware wallet company, warned users on September 10 that a third-party email provider had been breached, allowing attackers to send phishing emails impersonating the hardware wallet company.

The fraudulent messages, titled “Critical Security Alert: STM32 Entropy Vulnerability,” urged recipients to click links and claimed that a serious hardware security flaw had been discovered.

Trezor said the emails were not legitimate and advised users not to click on the links. The company also said it was sending an email update to affected users.

Fraudulent Emails Mimic a Legitimate Vulnerability Warning

Trezor said it had shut down the exploited domain and was investigating how the attackers obtained access to the infrastructure used in the phishing campaign.

Security firm PeckShield also reported that the phishing sender address was spoofed to appear as help@trezor.io 

The fraudulent emails claimed a “critical hardware-level vulnerability” existed in the STM32 microcontroller chips used in Trezor’s hardware wallets, falsely asserting that a quarter of devices were affected due to insufficient entropy in private key generation — a flaw that, if genuine, could potentially expose seed phrases and put users’ assets at risk.

Trezor confirmed that the phishing email asked recipients to share their wallet backup 

BitBox Also Warns of Phishing

Earlier that day, another hardware wallet company, BitBox, alerted users to phishing attempts using its brand.

BitBox, a Swiss hardware wallet manufacturer, reported that similar phishing emails impersonating the company were circulating that day.

Nick Neumann, co-founder and CEO at Bitcoin self-custody company Casa, suggested on X that a shared marketing email provider may have been compromised, potentially affecting Trezor, BitBox and other companies. 

“It’s likely that a marketing email provider was compromised. That will mean more customer emails are leaked.”

ShipMonk Data Breach

The phishing campaign follows a separate security incident involving Trezor last month.

In August 2026, Trezor was affected by a supply-chain attack in which personal information belonging to 80,689 customers was exposed through the company’s shipping contractor, ShipMonk.

The exposed information mostly included names, phone numbers and addresses, while 1,947 customers had only their names, cities and email addresses exposed.

Why This Matters

Phishing campaigns that impersonate trusted hardware wallet brands can trick users into revealing recovery phrases or wallet backups, potentially putting their crypto assets at risk. The incidents also highlight the security risks companies can face when third-party vendors handle customer communications and data.

Dive into DailyCoin’s hottest crypto news today:
Zcash Price Surges 2,496% as Privacy Becomes the Trade of the Year
Cardano Bulls Brace Themselves For a Bounce To $0.50

DailyCoin's Vibe Check: Which way are you leaning towards after reading this article?
Market Sentiment
100% Bullish