Trezor and BitBox warn users after phishing emails target wallet holders
Trezor and BitBox have warned users after phishing emails impersonating their brands hit inboxes through what appears to be compromised third-party email infrastructure. The bait was a fake “Critical Security Alert: STM32 Entropy Vulnerability” message, and the goal was the usual one, trick users into handing over their recovery phrases.
- Trezor warned users on Wednesday about a fake security alert email.
- BitBox issued a similar warning the same day.
- The scam used technical jargon to make the message look legitimate.
- The real target was the recovery phrase, also called a seed phrase.
Trezor said its third-party email service provider had been breached, while BitBox said its newsletter provider was “very likely” compromised. BitBox also said several Bitcoin companies appeared to have been targeted through the same shared provider.
That matters because these emails may not have come from some random throwaway domain. If attackers can abuse a legitimate mailing system, they can send messages that look far more convincing than the usual typo-riddled spam goblin nonsense. Spam filters help, but they are not magic.
The fake Trezor email leaned on a technical-sounding warning about entropy, which is the randomness used when creating wallet seeds. Strong entropy is critical. Weak entropy can make generated keys more predictable in extreme cases, and that is exactly the kind of scary phrase scammers love to weaponize.
The subject line itself was built to sound like a real security bulletin: “Critical Security Alert: STM32 Entropy Vulnerability.” STM32 refers to a family of microcontrollers, so the message borrows just enough technical language to sound credible to people who know a little bit about hardware wallets, and intimidating to everyone else.
Trezor told users not to click links in the fraudulent email and repeated a warning that should be common knowledge by now: we would never request their wallet backup.
“we would never request their wallet backup”
That is the whole game here. Hardware wallets are built to keep private keys offline, but they cannot stop a person from being manipulated into giving away the one thing that matters most. If someone gets your recovery phrase, they do not need to crack the device. They just walk in through the front door and take the money.
Why this phishing wave works
This kind of attack is not especially sophisticated, which is part of the problem. It does not need to be. It only needs to sound urgent, technical, and official enough to make a user act before thinking.
That is why the “entropy vulnerability” angle works so well. It borrows a real security concept and uses it as bait. A user who has heard about hardware-wallet randomness issues before may be more likely to panic, click, and “check” their wallet on a fake site. That is exactly what the attacker wants.
The threat also gets worse when customer data leaks are in the mix. Trezor previously disclosed that its logistics partner ShipMonk exposed customer information, including names, email addresses, phone numbers, shipping addresses and order numbers for more than 80, 000 customers in total. Trezor said its own systems were not breached and its hardware wallets, private keys and recovery phrases remained secure.
Even so, exposed metadata makes phishing more convincing. A scam email that knows your name, email address, shipping details, or order history does not have to work very hard to sound real. It just has to feel close enough to the truth.
Trezor also said attackers abused its contact form in June 2025 by submitting requests using targeted users’ email addresses, though the company said its internal email infrastructure had not been breached in that incident. Different tactic, same aim, make a fake message feel like it belongs.
Why the hardware-wallet sector keeps getting hit from the edges
This latest wave lands in a year that has already served up plenty of ugly reminders that hardware wallets are only one piece of the security puzzle.
Earlier in the year, a Coldcard firmware flaw showed how damaging weak randomness can be when seed generation goes wrong. The issue came from a build configuration error that caused devices to use a software pseudorandom number generator instead of a hardware random number generator. The affected Coldcard Mk3 firmware dated back to March 2021.
That is the kind of failure that should make the entire industry squirm. The cryptography may be fine. The implementation can still be a mess. And when seed generation is wrong, the result is not a minor bug, it is a wallet that may never have been safe in the first place.
Kraken Chief Security Officer Nick Percoco called for independent audits of hardware-wallet seed generation after the Coldcard issue. That is not paranoia. It is basic hygiene. If a device is responsible for creating the words that control the funds, “trust us” is not a security strategy. It is a surrender flag.
BitBox has also had its own firmware problems to deal with. In August, it patched two flaws, one that could have allowed malicious firmware to be installed under certain conditions, and another involving Bitcoin address handling. BitBox said there was no known exploitation of either vulnerability and no user funds were reported stolen.
The point is not that hardware wallets are broken. They are still one of the best tools available for self-custody. The point is that the real attack surface has moved outward. Attackers are probing email providers, newsletter services, shipping partners, contact forms, physical mail, QR codes, and anything else that can be used to get in front of the user.
This is also why the physical-letter scams from February mattered. Attackers impersonated Trezor and Ledger by mailing fake letters that pointed recipients to QR codes for supposed authentication or transaction checks. Those QR codes led to malicious websites asking for 12-, 20- or 24-word recovery phrases. Same trick, different costume.
Different channel. Same grift. The device can stay secure while the human gets mugged.
Why the provider compromise matters
One of the more annoying realities in crypto security is that trusted infrastructure can be abused against the people who trust it. A vendor’s own email platform, newsletter service, or support system can become the delivery vehicle for a scam.
That is especially nasty because the messages can sometimes look more legitimate to both users and filters. The sender may appear to be part of the normal company workflow, even if the content is malicious. In other words, the attack does not always need to hack the wallet company directly. It just needs to hijack a softer link upstream.
BitBox said its newsletter provider was “very likely” compromised and that multiple other Bitcoin companies appeared to have been targeted through the same provider. That points to a broader supply-chain problem rather than a single company-specific failure. When one mailing service gets popped, every brand using it can inherit the fallout.
And yes, that is a sober reminder that decentralization is still being forced to fight uphill against the boring parts of the internet: vendors, processors, logistics, and inboxes. Bitcoin may be censorship-resistant, but your newsletter platform can still be a clown car.
Key questions and takeaways
-
What did Trezor and BitBox warn users about?
Both companies warned about phishing emails impersonating their brands. Trezor said its third-party email provider had been breached, while BitBox said its newsletter provider was very likely compromised. -
What was the fake email trying to steal?
The recovery phrase, also called a seed phrase. Anyone who gets those words can take control of the wallet, and no legitimate support team should ever ask for them. -
Why did the scam mention “entropy” and “STM32”?
Because technical jargon makes a phish feel real. Entropy is the randomness used in wallet creation, and STM32 is a microcontroller family, so the whole thing sounds like a serious security bulletin. -
Were the hardware wallets themselves hacked?
Based on current warnings, the device hardware does not appear to be the issue. The problem is the attack surface around the device: email services, newsletter providers, shipping data, and user trust. -
Why does the ShipMonk exposure matter?
Because leaked customer metadata can make phishing much more convincing. Names, emails, shipping addresses and order numbers give attackers enough detail to craft messages that feel uncomfortably real. -
What is the main lesson for crypto users?
Hardware wallets reduce risk, but they do not eliminate social engineering or supply-chain attacks. If a recovery phrase is exposed, the wallet is cooked, no heroic recovery arc, just stolen funds and a very expensive lesson.
The uncomfortable truth is that most wallet thefts do not require genius-level hacking. They require a convincing lie, a moment of panic, and one user willing to type the wrong thing into the wrong place. Secure devices matter. So does the boring discipline of never trusting an email that asks for your backup words.
In crypto, the weakest link is often not the chain. It is the inbox.
Further reading on hardware-wallet phishing and security
A few useful links on wallet basics, phishing patterns, and prior hardware-wallet security incidents.
- Trezor and BitBox users targeted in newsletter phishing
- BitBox & Trezor entropy vulnerability warning phishing scams
- Cryptocurrency wallet basics
- Trezor and BitBox warn users after phishing emails
- D’Cent vs. Trezor: best hardware wallet for Bitcoin and crypto security
- Trezor patches critical flaw discovered by rival Ledger
- Ledger exposes Trezor Safe 3 and 5 supply-chain attack vulnerability