Hardware wallet manufacturers Trezor and BitBox issued warnings to users on Wednesday about phishing emails posing as urgent security alerts, following reports of third-party email service breaches that appear to have been exploited for fraudulent communications. Trezor attributed the phishing attempts to a breach of its email provider, stating a message titled ‘Critical Security Alert: STM32 Entropy Vulnerability’ was fake and urging recipients to avoid clicking any links. BitBox similarly warned users about a phishing email impersonating the company, citing preliminary evidence that its newsletter provider was compromised, with multiple Bitcoin-related firms targeted through a shared email service. These alerts followed recent security incidents in the hardware-wallet sector. On August 13, a breach at Trezor’s shipping partner ShipMonk exposed data for nearly 14,000 customers. On September 4, Trezor disclosed that another 67,000 US customers had been affected by a separate data breach. BitBox had previously addressed a vulnerability involving Coldcard’s random-number generation in July, though no exploitation or stolen funds were reported. In August, BitBox released a firmware update addressing two severe vulnerabilities without evidence of exploitation or fund theft. Cointelegraph reached out to both companies for further details but did not receive responses before publication.
Hardware wallet firms warn of phishing emails exploiting email breaches
Trezor and BitBox alert users to fraudulent security alerts linked to third-party email service compromises, amid broader sector security concerns
MW
Marcus Webb · Crypto Desk · 19 Sept 2026 · 09:05 · 1 min read
This article was produced with AI assistance and edited by a Finance Review Daily journalist.
ADVERTISEMENT

MW
Written by
Marcus Webb
Crypto Desk
Marcus reports on digital assets, from spot ETF flows to protocol-level developments in DeFi. He pays particular attention to how institutional adoption is reshaping crypto market structure.
More from Marcus Webb →









