Threat actors use fraudulent vulnerability warning to attack Trezor and BitBox users
Attackers impersonated Trezor and BitBox in phishing emails exploiting a fake hardware wallet vulnerability to target users, highlighting ongoing risks to cryptocurrency custody despite the wallet makers’ technical security. Both companies traced the breach to compromised third-party email and newsletter providers, raising questions about supply-chain vulnerabilities in the hardware wallet ecosystem.
- Trezor and BitBox issued phishing warnings on September 9 after attackers sent emails impersonating both brands with a fake “Critical Security Alert: STM32 Entropy Vulnerability” subject line.
- Trezor determined a third-party email provider had been breached; BitBox identified its newsletter provider as compromised and noted other Bitcoin companies were similarly targeted.
- Both companies emphasized that wallets remained secure but warned users never to share recovery seeds and to verify security guidance only through official channels.
- Sept. 9 Date both Trezor and BitBox publicly warned users about phishing emails impersonating their respective brands
- STM32 Technical processor name exploited in phishing subject line to create false authenticity and urgency
On September 9, hardware wallet providers Trezor and BitBox alerted their user bases to a coordinated phishing campaign impersonating both companies’ brands. The fraudulent emails arrived with a technical-sounding subject line, “Critical Security Alert: STM32 Entropy Vulnerability,” designed to trigger urgency and exploit users’ trust in legitimate security warnings from wallet manufacturers. Neither company issued the messages, and both explicitly instructed recipients to ignore links and instructions contained within them.
The phishing campaign represents a notable shift in attacker tactics within the cryptocurrency ecosystem. Rather than targeting the cryptographic protocols or hardware components that secure digital assets, malicious actors focused on compromising the communication channels through which wallet providers interact with their users. This approach exploits the trust relationship between manufacturers and customers, leveraging the expectation that security announcements will come through official channels.
Third-Party email infrastructure compromised across multiple Wallet providers
Trezor pinpointed the origin of the attack on September 10, revealing that a third-party email provider handling its communications had been breached. The company stated that its wallet infrastructure remained uncompromised despite the unauthorized access to its email systems and that it had taken down the fraudulent domain used in the campaign while investigating how attackers gained access to legitimate Trezor domains.
BitBox’s investigation yielded a similar finding: its newsletter service provider had been compromised. Critically, BitBox determined that the breach extended beyond its own systems, noting that other Bitcoin companies shared the same newsletter provider and had also been targeted. This discovery suggests the attackers may have deliberately targeted a shared vendor to maximize their reach across the industry with a single breach.
BitBox said it had notified all newsletter subscribers, contacted the affected provider directly, and reported the phishing domains to appropriate authorities. By the time of BitBox’s update on September 9, most phishing links had been taken down, though the company indicated its investigation was ongoing.
The incident highlights a structural vulnerability in the hardware wallet industry’s operational security posture. Hardware wallet manufacturers have invested substantially in securing the devices themselves through secure chip design, firmware verification, and cryptographic protocols. However, the supply chain for business services supporting these companies, including email and communication infrastructure, often receives less attention and resources than the core product security teams.
Recovery seed protection remains critical regardless of email Security
While both companies reassured users that their wallet devices themselves had not been compromised, the incident underscores a fundamental vulnerability in hardware wallet security: anyone with access to a user’s recovery seed, also called a backup, can gain full control of the funds. Trezor’s official security guidance emphasizes that users must never share their recovery seed under any circumstances and should verify any wallet-related security concerns only through official company channels rather than links provided in email.
The phishing emails likely aimed to trick users into revealing their recovery seeds or installing malicious software. Social engineering attacks that exploit legitimate security concerns remain one of the most effective methods for compromising cryptocurrency holdings, even when the underlying technology is sound. Users who fell for the phishing scheme and entered their recovery seeds into fraudulent websites would have exposed their funds to immediate theft.
Trezor recommends that users download Trezor Suite exclusively from its official website and avoid clicking suspicious links or downloading attachments from unsolicited messages. Best practices for cryptocurrency security include treating any unexpected security alerts with skepticism, even when they appear to come from trusted sources, and independently verifying urgent claims through official company websites.
For affected users, the immediate action is to disregard all instructions in the phishing emails and maintain strict confidentiality of recovery words. Any follow-up questions about the incident should be directed to official Trezor or BitBox websites and verified through those channels rather than through email links, as both companies continue their investigations into the scope of the breach and the identity of the attackers. Users concerned about potential exposure should monitor their accounts for unauthorized activity and consider moving funds to a fresh wallet if they believe their recovery seed may have been compromised.
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
