2026-09-10 CoinTelegraph

Trezor and BitBox Warn Users of Fake Security Emails

Trezor and BitBox have issued warnings about phishing emails disguised as urgent security alerts following suspected compromises involving third-party email service providers. Trezor said its email provider was breached and identified a fraudulent message titled “Critical Security Alert: STM32 Entropy Vulnerability.” The company urged recipients not to open the email or click any links.

BitBox reported a separate phishing campaign using a message that appeared to come from the hardware-wallet maker. Its preliminary investigation indicated that the company’s newsletter provider was likely compromised, with several Bitcoin businesses possibly targeted through a shared service provider. Trezor and BitBox had not responded to requests for additional information before publication.

The warnings followed other security incidents involving the hardware-wallet sector. A breach at Trezor shipping provider ShipMonk on Aug. 13 exposed data belonging to nearly 14,000 customers, while Trezor later said another 67,000 U.S. customers were affected in a separate incident. BitBox also said its devices were unaffected by a vulnerability involving Coldcard’s random-number generation and released an update addressing two severe firmware vulnerabilities in August. No known exploitation or stolen funds were reported in connection with those BitBox vulnerabilities.

Read Full Article at CoinTelegraph →

Related Tool

Find Your ID

Try Now →
Check My ID