Hardware wallet makers Trezor and BitBox said on September 9 that they were hit by a wave of phishing emails disguised as urgent security notices. Both companies suspect a breach at third-party email providers used to send the fraudulent messages.
What exactly happened to Trezor's email?
Trezor said its email newsletter provider had been breached. Hackers sent a message titled "Critical Security Alert: STM32 Entropy Vulnerability" that falsely claimed a chip flaw could expose a user's seed phrase. The company called the email fake and urged recipients not to click any links inside it.
BitBox faced a similar issue the same day. Based on the company's preliminary review, its newsletter provider appeared to be compromised, and several hardware wallet makers using the same platform were targeted at once. BitBox did not name the other affected companies.
The subject line was not random. STM32 microcontrollers are genuinely used in some Trezor devices, so the wording looked credible even to technically savvy users. Such details make crypto phishing especially dangerous, since scammers tailor their terminology to a specific brand.
Campaigns like this one are rarely personalized. Attackers blast the same message to thousands of addresses at once, betting that a fraction of recipients will panic and click. Hardware wallet owners are an attractive target precisely because they've already invested in self-custody and tend to take any warning about a device flaw seriously.
Both companies said the same thing: the devices and firmware themselves remain secure. What got breached was marketing infrastructure, not the servers holding user keys or the wallet hardware.
How can users spot a phishing email like this?
The fake Trezor email had every hallmark of a classic attack on crypto holders. An urgent tone, technical jargon and a link to an "official" firmware update all made it look convincing. The email aimed to get recipients to open a page mimicking the maker's site and enter their seed phrase to "verify" the wallet.
Here is the key detail: no legitimate maker, including Trezor, BitBox or Ledger, will ever ask for a seed phrase by email, in a support chat or on a third-party website. The private key protecting Bitcoin and other assets is meant to stay on the device itself, nowhere else.
BitBox added that the emails came from addresses resembling its official ones but with minor domain differences. That's a common trick for slipping past spam filters. The company advised customers to check any security notice directly on its official website instead of clicking links in an email.
- Rule of thumb: A request for a seed phrase or private key through any channel other than the device itself is a scam.
- Links that lead to a domain with unusual spelling or extra characters.
- A manufactured sense of urgency, such as demands to update immediately or warnings that funds are "at risk."
- Instructions to install a firmware update via a link in the email instead of the official site or app.
- A sender address that only slightly differs from the company's real domain.
Why is this attack tied to Trezor's earlier data leaks?
This marks the third security disclosure from Trezor in a month. On August 13, the company confirmed a breach at ShipMonk, its logistics partner, which exposed data belonging to roughly 14,000 customers. On September 4, Trezor disclosed another incident. This time, data belonging to 67,000 US users was affected.
Each of those leaks typically included names, mailing addresses and order numbers. That's enough to craft a convincing phishing email referencing a real purchase of a specific device. The timeline suggests the September 9 attack likely drew on that same earlier stolen contact data.
BitBox has its own backstory. In July, the company said its devices were unaffected by a random-number generator flaw found in Coldcard. In August, it shipped a firmware update fixing two severe vulnerabilities, with no reports of stolen funds at the time.
Supply-chain-style attacks through third-party vendors are becoming more common across the crypto industry. A single breached email service or CRM platform can hit the customer bases of several unrelated brands at once, with a shared contractor as the only link between them.
What should hardware wallet owners do now?
Trezor and BitBox promised to share more investigation details in the coming days. Both companies want to make one thing clear to worried customers. The device itself and the private key stored on it are untouched by phishing, and only users who click the fake link and manually enter their seed phrase are at risk.
A passphrase, available on most modern hardware wallets, adds another layer of protection: even if someone learns the base seed phrase, they still can't reach the funds without the extra password. Both companies also recommend typing the manufacturer's website address into a browser by hand instead of clicking links from an email.
For anyone holding assets in self-custody rather than on an exchange, emails like these are a primary attack vector. Losing a seed phrase means losing access to funds permanently, with no support team able to restore it.
Hardware wallet owners should check recent emails claiming to be from their manufacturer, delete anything suspicious, and reach out to official support directly through the company website rather than following a link from an email.




Comments
Your email address will not be published. Required fields are marked *