Trezor, BitBox Warn Users After Phishing Emails Target Wallet Holders

Published:

Hardware wallet makers Trezor and BitBox have warned customers about a phishing campaign that used legitimate-looking email infrastructure to distribute fake security alerts.

The campaign surfaced on Sept. 9, with messages claiming that Trezor devices faced a critical vulnerability involving STM32 chips and weak wallet seeds. Trezor said its third-party email provider had been breached and urged recipients not to click links in the message.

The incident highlights a growing risk for crypto users: phishing emails can appear authentic even when attackers have compromised a trusted marketing platform.

Fake Security Alerts Raise Concern

The fraudulent Trezor message reportedly encouraged recipients to check whether their devices were affected. Some versions directed users toward pages that sought wallet-related information.

Trezor has not confirmed that its hardware, private keys, or recovery backups were compromised in the incident. The company said it had taken down the malicious domain and was investigating the breach.

BitBox also warned its newsletter subscribers after identifying a similar campaign. The company said its preliminary investigation indicated that its newsletter provider was likely compromised. Other Bitcoin companies may have used the same service.

For wallet holders, the warnings carry several clear lessons:

  • Never enter recovery words on a website.
  • Do not follow unexpected wallet-security links or QR codes.
  • Verify security announcements through an independently opened official website.
  • Treat urgent requests for wallet information as potential phishing attempts.

Third-Party Services Become a Key Risk

The campaign shows how attackers can target cryptocurrency users without directly compromising wallet hardware. Instead, criminals can exploit companies that manage customer communications.

That approach can make fraudulent messages more convincing because they may pass normal email authentication checks. Users therefore cannot rely solely on sender names, familiar branding, or an apparently legitimate email address.

The attacks also come after Trezor disclosed a separate customer-data breach involving a third-party shipping provider. That incident exposed contact information belonging to thousands of customers and increased concerns about targeted phishing.

For crypto investors, the latest campaign reinforces a basic security principle: hardware wallets can protect private keys, but users still need to defend themselves against social engineering. A genuine wallet manufacturer will not ask customers to reveal recovery phrases through email or a website.

Raj Sharma
Raj Sharma
I have been involved in the blockchain industry for over 5 years and have an extensive understanding of the technology. My career in cryptocurrency started with writing articles about blockchain technology and its use cases for various publications.

Related News

Recent