Trezor, BitBox warn users of fake security alerts from newsletter breaches
In brief
- Trezor's email provider breached; phishing email falsely warned of STM32 vulnerability
- BitBox detected phishing email from compromised newsletter provider
- Multiple crypto companies targeted through shared newsletter service compromise
Email provider compromises lead to phishing wave
Trezor said its email provider had been breached and warned that a message titled "Critical Security Alert: STM32 Entropy Vulnerability" was fraudulent. The email impersonated Trezor and attempted to trick users into believing their devices had a critical flaw. It didn't.
BitBox warned users about a phishing email pretending to come from the company. The company's preliminary review indicated that its newsletter provider was likely compromised. More concerning: multiple Bitcoin companies appeared to have been targeted through the same shared provider.
Neither company responded to requests for additional details before publication.
Recent security incidents compound concerns
This latest breach follows a pattern of security incidents at both firms. On August 13, a breach at Trezor shipping provider ShipMonk exposed data belonging to nearly 14,000 customers. Weeks later, on September 4, Trezor disclosed that another 67,000 US customers were affected by a security incident.
BitBox has also dealt with firmware issues. In July, BitBox said its devices were unaffected by a vulnerability involving Coldcard's random-number generation. In August, it released an update fixing two severe firmware vulnerabilities, with no known exploitation or stolen funds reported.
The phishing emails highlight a persistent threat. Even when hardware wallets themselves remain secure, the human element—email providers, shipping partners, newsletter services—creates attack surface. Users should verify any security alert through official channels before taking action.


