Trezor and BitBox warn users of phishing emails mimicking security alerts
Phishing emails impersonate hardware‑wallet makers
On September 10, 2026, the hardware‑wallet manufacturers Trezor and BitBox issued warnings that users had received fake security alerts. The messages were sent through compromised email services and tried to look urgent.
Key facts
- Trezor’s email provider was breached; a fraudulent email titled “Critical Security Alert: STM32 Entropy Vulnerability” was sent to users.
- BitBox’s newsletter provider appears to have been compromised, affecting multiple Bitcoin‑related companies.
- Both companies advised recipients not to click any links in the messages.
Trezor’s official warning
Trezor posted on X that its email service was breached and that the “Critical Security Alert: STM32 Entropy Vulnerability” email is fake. The company urged users to ignore the message and avoid clicking any links.
BitBox’s official warning
BitBox also posted on X that a phishing email pretending to be from the company was sent. A preliminary review suggests the breach originated from its shared newsletter provider, which may have also targeted other Bitcoin companies.
Recent security incidents affecting hardware wallets
These warnings follow other recent disclosures. On August 13, a breach at Trezor’s shipping partner ShipMonk exposed data of about 14,000 customers. On September 4, Trezor reported that another breach affected roughly 67,000 U.S. customers. In July, BitBox confirmed its devices were not affected by a Coldcard random‑number‑generation vulnerability, and in August it released a firmware update fixing two serious issues.
Why this matters
Hardware wallets store private keys offline, protecting crypto assets. Phishing emails that appear to be official security alerts can trick users into revealing passwords or installing malicious software, potentially compromising their funds.