Crypto news report · source clearly identified

Phishing Campaign Exploits Compromised Email Providers to Target Trezor, Bitbox and Cointracking Users

Trezor, Bitbox and Cointracking warned customers on September 10 that phishing emails sent through a breached third‑party mailing service impersonated official security notices, aiming to steal information from cryptocurrency users.

Incident overview

On September 9‑10, users of three crypto‑related services received phishing emails that appeared to be legitimate security alerts. The messages were sent via a compromised email‑service provider and contained malicious links designed to harvest personal data.

Companies’ responses

Trezor

Trezor alerted customers that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” did not originate from the hardware‑wallet maker. The company said its third‑party email provider had been breached and that attackers had also gained access to Trezor’s own domain, making the fake message harder to detect. The malicious domain has been taken down and an investigation is ongoing.

Bitbox

Bitbox reported that its newsletter provider was likely compromised, affecting multiple Bitcoin‑focused firms that use the same service. The company issued its own phishing warning, contacted the provider and reported the malicious domains. Most phishing links were already removed when Bitbox issued its statement, but the investigation continues.

Cointracking

Cointracking identified the third‑party email service Brevo as the source of its phishing incident. Customers received a bogus “Data Breach Notice: Please refresh API Keys as soon as possible” email. Cointracking warned users not to click any links and said it was investigating the breach.

Broader context

Recent leaks at hardware‑wallet providers—including a SafePal authorization flaw affecting roughly 40,000 customers and a Trezor shipping‑partner breach impacting about 81,000 orders—have increased the amount of personal data available to attackers, making phishing attempts more convincing. The rise of AI‑driven vulnerability research is also accelerating the discovery of software flaws across the crypto ecosystem.

What users should do

  • Avoid clicking links in any unexpected security‑alert emails from Trezor, Bitbox or Cointracking.
  • Verify the sender’s address independently, especially if the email appears to come from a familiar domain.
  • Monitor official communications from the affected companies for updates.

Source & attribution

News Source

Publisher
Bitcoin.com News
Original date
September 10, 2026, 10:30 AM
Original headline
Hackers Hijack Trezor, Bitbox Emails to Target Crypto Users
View original report ↗