On September 9 2026, two leading hardware‑wallet makers, Trezor and BitBox, issued public warnings that phishing emails were being sent from their legitimate domains. The emails were created after a breach at a third‑party email and newsletter provider used by both companies.

The phishing messages falsely claimed a critical security issue with Trezor devices. The subject line read “Critical Security Alert: STM32 Entropy Vulnerability,” a title that was not issued by Trezor. The emails urged recipients to click a link and update their wallets. Trezor confirmed that the message did not originate from the company and advised users not to click any links. The company also stated that its wallets remain secure and that the breach involved only the email provider.

BitBox issued a similar notice on the same day. Its preliminary investigation indicated that the newsletter provider it uses had been compromised. BitBox said that other Bitcoin‑related companies appeared to have been targeted through the same provider. The company reported that most phishing links had been taken down by the time of its update, but the investigation was still ongoing.

Both companies took immediate action to mitigate the threat. Trezor shut down the domain that was used to send the phishing emails and began an investigation into how attackers accessed its legitimate mailing infrastructure. BitBox contacted its newsletter provider, warned all subscribers, and reported the phishing domains to the relevant authorities.

The incidents highlight a risk that is often overlooked in hardware‑wallet security discussions: the recovery seed, or backup phrase, is the only credential that can move funds from a wallet. If a phishing email convinces a user to reveal or type that seed into a malicious site, the attacker can drain the wallet. Trezor’s official guidance reiterates that users should never share their recovery seed and should verify any security claim through the company’s official website or support channels.

The breach is part of a series of security incidents that have affected multiple vendors in the crypto space over the past month. Earlier in August, Trezor disclosed a separate data breach at its shipping partner ShipMonk, which exposed customer order information. The September email‑provider breach is the third major vendor failure involving Trezor in four weeks.

Industry analysts note that the use of a legitimate domain and passing SPF, DKIM, and DMARC checks makes such phishing campaigns more convincing. The attackers were able to send emails that appeared to come from Trezor’s own domain, which can lower the barrier for users to trust the message.

At present, no evidence indicates that any wallets have been compromised or that funds have been stolen. Both Trezor and BitBox have not reported any loss of user funds. The companies are continuing to investigate the extent of the breach and the number of affected users.

Users who received the phishing emails are advised to delete the messages, avoid clicking any links or downloading attachments, and verify any security claim by visiting the official Trezor or BitBox website. They should also review their recovery seeds and ensure that the phrases are stored in a secure, offline location.

The incidents underscore the importance of robust email security practices for crypto companies and the need for users to remain vigilant against phishing attempts that exploit legitimate brand names.