Crypto news report · source clearly identified
Trezor and BitBox Alert Users to Phishing Emails After Email Service Breaches
BitBox said multiple Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor confirmed a breach at its email service.

Hardware wallet manufacturers Trezor and BitBox have warned their users about phishing emails that masquerade as urgent security alerts. Both warnings stem from suspected compromises of third‑party email services used by the companies.
Phishing email details
Trezor reported that its email provider was breached and that a fraudulent message titled “Critical Security Alert: STM32 Entropy Vulnerability” was circulated. Recipients were instructed not to click any links in the email.
BitBox issued a similar warning, noting that a phishing email appeared to come from the company. A preliminary review suggested that the newsletter provider used by BitBox – and shared with other Bitcoin‑related firms – may have been compromised.
Recent security incidents in the hardware‑wallet sector
- On August 13, a breach at Trezor’s shipping partner ShipMonk exposed data of nearly 14,000 customers.
- On September 4, Trezor disclosed that an additional 67,000 U.S. customers were affected by a separate incident.
- In July, BitBox confirmed its devices were not impacted by a vulnerability affecting Coldcard’s random‑number generation.
- In August, BitBox released a firmware update addressing two severe vulnerabilities; no exploitation or fund loss has been reported.
Company responses
Both firms have urged users to verify the authenticity of any security‑related communications and to avoid clicking links in suspicious emails. Cointelegraph contacted Trezor and BitBox for further comment but had not received a response at the time of publication.
Source & attribution
News Source
- Publisher
- Cointelegraph
- Original date
- September 10, 2026, 5:34 AM
- Original headline
- Trezor, BitBox warn users about fake hardware wallet security alerts