Trezor and BitBox Warn Users of Phishing Campaign Targeting Wallet Holders
Security
Neutral

Trezor and BitBox Warn Users of Phishing Campaign Targeting Wallet Holders

Trezor and BitBox warned users Wednesday of phishing emails impersonating security alerts, exploiting breaches at third-party email and newsletter providers. Both hardware wallet makers confirmed users' funds remain secure and advised recipients to verify communications directly through official channels.

Sep 11, 2026, 09:05 AM1 min read

Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work

The Phishing Campaign

Trezor and BitBox confirmed Wednesday that attackers are targeting wallet holders with phishing emails disguised as urgent security notices. The fraudulent messages falsely alert recipients to a vulnerability in STM32 microcontrollers — the chips used in both companies' hardware wallets — and attempt to direct users to malicious sites.

Trezor said its email provider had been breached, while BitBox is investigating a likely compromise of its newsletter provider. Both companies emphasized that the alerts themselves are fake and that no actual STM32 vulnerability poses a risk to their devices.

User Safety and Official Guidance

Both Trezor and BitBox confirmed that user funds stored on their hardware wallets remain secure and that the phishing campaign does not compromise the devices themselves. The companies advised users not to click links in unsolicited emails claiming to be from either wallet maker and to verify any security communications by visiting official websites directly or contacting support through verified channels.

The breach of third-party email infrastructure underscores how attackers can exploit supply-chain access to reach user bases at scale, even when the primary product itself remains uncompromised.

Why It Matters

For Traders

No loss of funds is implied, but traders should verify any security alerts independently before moving assets or changing operational security.

For Investors

Third-party email and newsletter provider breaches demonstrate operational risk vectors that hardware wallet companies must actively monitor and mitigate.

For Builders

Infrastructure providers serving crypto platforms should assume they are phishing targets; contractual SLAs and breach-notification timelines should be stress-tested accordingly.

This article is for information only and is not financial advice. Read the full disclaimer.

Related Articles

Latest News