Trezor and BitBox Users Targeted in Coordinated Hardware Wallet Phishing Campaign

10-Sep-2026 Crypto Adventure
Trezor and BitBox Users Targeted in Coordinated Hardware Wallet Phishing Campaign

Trezor and BitBox users are being targeted by a coordinated phishing campaign built around fake hardware-wallet security warnings. Attackers breached Trezor’s third-party email provider and distributed a message titled “Critical Security Alert: STM32 Entropy Vulnerability.”

The email falsely claims a factory defect in STM32 microcontrollers weakened recovery-phrase generation on roughly one in four Trezor devices. Recipients are pushed toward a vulnerability-check page that can collect wallet information or recovery words. Trezor took down the phishing domain, while its hardware wallets, private keys and recovery backups remain secure.

BitBox users received a closely related “Microcontroller Entropy Vulnerability” message. Its preliminary investigation points to a compromised newsletter provider shared by several Bitcoin companies, while most identified phishing links were taken offline. Technical traces from the campaign showed Brevo/Sendinblue routing, although neither wallet maker publicly named Brevo as the compromised provider in its initial warning.

No Confirmed Losses Reported Yet

No confirmed user losses from the campaign had surfaced by September 10. Several users said they clicked the phishing link but stopped before entering sensitive data, with no wallet drain identified in those public reports.

BitBox advises anyone who entered recovery words to treat the wallet as compromised and move remaining funds to a freshly generated wallet. Simply receiving the email or opening a link without entering information does not by itself expose the recovery phrase.

Real Wallet Flaws Give the Scam Credibility

The campaign follows genuine wallet-security disclosures that give the fake warnings a more credible appearance. BitBox patched two severe vulnerabilities in August, including a memory-corruption issue and an older bootloader weakness that could support malicious firmware installation under specific conditions. BitBox had no known stolen funds tied to those flaws.

Trezor has separately dealt with a ShipMonk breach whose scope recently expanded by about 67,000 U.S. customers. Names, emails, phone numbers, shipping addresses and order information were exposed, increasing the amount of personal data available for targeted phishing, although Trezor’s wallet systems and backups were not compromised.

The fake entropy warning also echoes the Coldcard weak-seed failure that produced more than 1,778 BTC in high-confidence thefts and prompted emergency firmware changes in August. Trezor continues investigating access to its email infrastructure, while BitBox has contacted its newsletter provider and reported the phishing domains.

The post Trezor and BitBox Users Targeted in Coordinated Hardware Wallet Phishing Campaign appeared first on Crypto Adventure.

Also read: Hunter Biden Laptop Controversy Spurs New Memecoin Launch
WHAT'S YOUR OPINION?
Related News