Trezor, BitBox warn users about fake hardware wallet security alerts

BitBox said multiple Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor confirmed a breach at its email service.

Hardware wallet makers Trezor and BitBox warned users about phishing emails disguised as urgent security notices after suspected compromises involving third-party email services.

On Wednesday, Trezor said its email provider had been breached and warned that a message titled “Critical Security Alert: STM32 Entropy Vulnerability” was fraudulent. The company urged recipients not to click any links.

On the same day, Bitbox warned users about a phishing email pretending to come from the company. The company said its preliminary review indicated that its newsletter provider was likely compromised, adding that multiple Bitcoin companies appeared to have been targeted through a shared provider.

Read more

Cryptocurrency News

Author

  • Crystal Kim is a New York-based markets and investing reporter with more than 10 years of experience. Prior to joining Investopedia in July 2025, she covered crypto for Axios.

Crystal Kim

Crystal Kim is a New York-based markets and investing reporter with more than 10 years of experience. Prior to joining Investopedia in July 2025, she covered crypto for Axios.