Trezor and BitBox have warned customers not to respond to phishing emails posing as urgent security alerts, after suspected breaches at third-party email and newsletter providers.
Trezor said its email provider had been compromised and urged users not to click links in a fraudulent message entitled “Critical Security Alert: STM32 Entropy Vulnerability”. BitBox issued a similar warning after subscribers received emails impersonating the company.
BitBox said its initial investigation indicated that its newsletter provider was likely compromised. Several Bitcoin companies appeared to have been targeted through the same provider, it added.
The warnings come amid a series of security incidents affecting hardware wallet users, including a breach at shipping company ShipMonk that exposed information linked to more than 80,000 Trezor customers.
Trezor phishing email uses vulnerability claim
The fake Trezor email claimed that an STM32 entropy vulnerability required users to take immediate action.
Trezor confirmed that the message was fraudulent and said recipients should not interact with any of its links. The company attributed the incident to a breach at the external email provider used to distribute the message.
The campaign took advantage of concerns raised by a genuine entropy-related vulnerability affecting another hardware wallet manufacturer earlier this year.
In July, a Coldcard firmware flaw was disclosed involving weak random-number generation. The problem meant affected devices could create vulnerable wallet seeds.
The issue was caused by a build configuration error. Instead of using the intended hardware random-number generator, some Coldcard devices used a software pseudorandom-number generator. The vulnerability affected Coldcard Mk3 firmware dating back to March 2021.
Attackers later exploited the weakness to identify wallets created with vulnerable seeds. An attack on 31 July initially moved 594 BTC, worth about $38m at the time, from approximately 500 addresses. Subsequent analysis linked more addresses and Bitcoin to the same vulnerability.
The Coldcard incident prompted Kraken chief security officer Nick Percoco to call for independent audits of hardware wallet seed generation, as previously reported by crypto.news.
Coinkite released firmware fixes, but users whose wallets had been created with vulnerable seeds still needed to generate new seed phrases and transfer their Bitcoin.
BitBox said in July that its devices were not affected by the random-number generation vulnerability.
BitBox investigates newsletter provider
BitBox said phishing emails had been sent to users while pretending to come from the hardware wallet company.
Its preliminary investigation suggested that its newsletter provider had been compromised. The company said several other Bitcoin businesses appeared to have been targeted and were using the same provider.
BitBox warned subscribers about the campaign and said its investigation was continuing.
The warning followed a separate security disclosure in August, when BitBox fixed two serious firmware vulnerabilities affecting its hardware wallets.
One flaw could, under certain conditions, have allowed malicious firmware to be installed. The other concerned the handling of Bitcoin addresses and could have affected the way those addresses were verified.
BitBox said neither vulnerability had been known to have been exploited and that no user funds had been reported stolen. Firmware updates were issued to address both problems.
Hardware wallet users have also been targeted without the devices themselves being breached. In some cases, attackers impersonate manufacturers and try to persuade customers to reveal their recovery information.
In February, fake letters appearing to come from Trezor and Ledger instructed recipients to scan QR codes for supposed authentication or transaction checks. The letters used official-looking designs and deadlines to create a sense of urgency.
The QR codes led to malicious websites that asked users to submit 12-, 20- or 24-word recovery phrases, supposedly to verify ownership of a wallet.
Anyone who obtains a recovery phrase can recreate the associated wallet and control its funds. Trezor and Ledger have said legitimate hardware wallet providers will never ask customers to enter, scan, upload or share recovery phrases through websites or other external channels.
More than 80,000 Trezor customers affected by ShipMonk breach
Trezor’s latest warning follows separate disclosures concerning customer data held by its shipping provider, ShipMonk.
On 13 August, Trezor said unauthorised access to ShipMonk’s systems had exposed information belonging to 13,689 customers.
The initial disclosure involved 11,742 customers whose names, email addresses, telephone numbers and shipping addresses had been exposed. A further 1,947 customers had their names, cities and email addresses compromised.
Trezor said its own systems had not been breached and that its hardware wallets, private keys and recovery phrases remained secure. However, it warned that the exposed information could be used to make phishing and impersonation attempts more convincing.
On 4 September, Trezor expanded its disclosure after learning that approximately 67,000 additional customers in the United States had been affected.
The additional records related to orders placed between November 2019 and August 2021. They included names, email addresses, telephone numbers, shipping addresses and order numbers.
Together with the customers identified in August, the updated figures mean that more than 80,000 people were affected by the ShipMonk breach.
Trezor said it had previously been assured that the older customer information had been deleted from ShipMonk’s systems. The company learned on 2 September that the records had remained stored by the shipping provider.
The ShipMonk incident was also referenced in earlier coverage of the BitBox firmware vulnerabilities, alongside a separate customer data exposure involving hardware wallet maker SafePal. Neither incident compromised the companies’ hardware wallets or recovery phrases.
Earlier Trezor contact-form attack
The latest incident is not the first time Trezor users have been targeted through the company’s communications channels.
In June 2025, attackers abused Trezor’s contact form by submitting requests using the email addresses of selected users. Trezor’s system then generated automatic replies that appeared to come from its legitimate support infrastructure.
The approach made the phishing messages seem more credible because recipients received communications associated with Trezor’s normal support process.
Trezor said at the time that its internal email infrastructure had not been breached. It reminded users that the company would never ask for a wallet backup and that recovery information should be kept private and offline.
In the latest cases, both Trezor and BitBox have instead pointed to compromises involving external email services. BitBox said several Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor confirmed that its email provider had been breached.
