Crypto news report · source clearly identified
Phishing Campaign Exploits Compromised Email Providers to Target Trezor, Bitbox and Cointracking Users
Trezor, Bitbox and Cointracking warned customers on September 10 that phishing emails sent through a breached third‑party mailing service impersonated official security notices, aiming to steal information from cryptocurrency users.

Incident overview
On September 9‑10, users of three crypto‑related services received phishing emails that appeared to be legitimate security alerts. The messages were sent via a compromised email‑service provider and contained malicious links designed to harvest personal data.
Companies’ responses
Trezor
Trezor alerted customers that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” did not originate from the hardware‑wallet maker. The company said its third‑party email provider had been breached and that attackers had also gained access to Trezor’s own domain, making the fake message harder to detect. The malicious domain has been taken down and an investigation is ongoing.
Bitbox
Bitbox reported that its newsletter provider was likely compromised, affecting multiple Bitcoin‑focused firms that use the same service. The company issued its own phishing warning, contacted the provider and reported the malicious domains. Most phishing links were already removed when Bitbox issued its statement, but the investigation continues.
Cointracking
Cointracking identified the third‑party email service Brevo as the source of its phishing incident. Customers received a bogus “Data Breach Notice: Please refresh API Keys as soon as possible” email. Cointracking warned users not to click any links and said it was investigating the breach.
Broader context
Recent leaks at hardware‑wallet providers—including a SafePal authorization flaw affecting roughly 40,000 customers and a Trezor shipping‑partner breach impacting about 81,000 orders—have increased the amount of personal data available to attackers, making phishing attempts more convincing. The rise of AI‑driven vulnerability research is also accelerating the discovery of software flaws across the crypto ecosystem.
What users should do
- Avoid clicking links in any unexpected security‑alert emails from Trezor, Bitbox or Cointracking.
- Verify the sender’s address independently, especially if the email appears to come from a familiar domain.
- Monitor official communications from the affected companies for updates.
Source & attribution
News Source
- Publisher
- Bitcoin.com News
- Original date
- September 10, 2026, 10:30 AM
- Original headline
- Hackers Hijack Trezor, Bitbox Emails to Target Crypto Users