NewsCryptoCoordinated Phishing Campaign Targets Trezor and BitBox Hardware Wallet Users

Coordinated Phishing Campaign Targets Trezor and BitBox Hardware Wallet Users

Author: Crypto Adventure·

Key Takeaways

  • Attackers breached third-party email providers used by Trezor and BitBox to send fake entropy vulnerability warnings that reached customer inboxes through normally trusted channels.
  • The fraudulent messages directed users to a fake vulnerability-check page designed to collect recovery phrases, which can be used to recreate a wallet and spend its funds.
  • Trezor took down the phishing domain and stated its hardware wallets, private keys, and recovery backups remain secure, while BitBox's preliminary investigation points to a newsletter provider shared by several Bitcoin companies, with technical traces showing Brevo/Sendinblue routing.
  • No confirmed user losses had surfaced as of September 10, and BitBox advised anyone who entered recovery words on the fraudulent page to treat the wallet as compromised and move funds to a newly generated wallet.
  • The campaign exploited credibility from recent real disclosures, including BitBox's two patched vulnerabilities in August, the Trezor ShipMonk breach expanded by roughly 67,000 U.S. customers, and the Coldcard weak-seed failure tied to more than 1,778 BTC in thefts.
Coordinated Phishing Campaign Targets Trezor and BitBox Hardware Wallet Users

Users of hardware wallet makers Trezor and BitBox are being targeted by a coordinated phishing campaign built around fake security warnings. Attackers breached Trezor's third-party email provider and distributed a message titled “Critical Security Alert: STM32 Entropy Vulnerability,” while BitBox users received a closely related “Microcontroller Entropy Vulnerability” email. Because the messages went out through compromised providers that the companies use for legitimate mail, they reached customer inboxes through channels users had little reason to distrust.

The fraudulent Trezor message falsely claims a factory defect in STM32 microcontrollers weakened recovery-phrase generation on roughly one in four Trezor devices. Recipients are directed to a vulnerability-check page designed to collect wallet information or recovery words. Trezor took down the phishing domain and stated that its hardware wallets, private keys, and recovery backups remain secure. The recovery words are the target for a reason: as the master backup of a hardware wallet, a phrase in an attacker's hands can be used to recreate the wallet elsewhere and spend the funds it protects.

BitBox's preliminary investigation points to a compromised newsletter provider shared by several Bitcoin companies, and most identified phishing links have been taken offline. That shared vendor footprint meant one compromise was enough to put matching phishing messages in front of customers of multiple companies in a single wave. Technical traces from the campaign showed Brevo/Sendinblue routing, although neither wallet maker publicly named Brevo as the compromised provider in its initial warning. Trezor disclosed the incident in a PSA on its official subreddit, and BitBox published an update on r/BitBoxWallet along with official guidance on responding to phishing attempts.

No Confirmed Losses Reported

No confirmed user losses from the campaign had surfaced as of September 10. Several users said they clicked the phishing link but stopped before entering sensitive data, and no wallet drain was identified in those public reports.

BitBox advises anyone who entered recovery words on the fraudulent page to treat the wallet as compromised and move remaining funds to a freshly generated wallet. Simply receiving the email or opening the link without entering information does not by itself expose the recovery phrase.

Real Wallet Flaws Give the Scam Credibility

The campaign follows genuine wallet-security disclosures that give the fake warnings a more credible appearance. In August, BitBox patched two severe vulnerabilities, including a memory-corruption issue and an older bootloader weakness that could support malicious firmware installation under specific conditions. BitBox had no known stolen funds tied to those flaws.

Trezor has separately dealt with a ShipMonk breach whose scope recently expanded by about 67,000 U.S. customers. Names, emails, phone numbers, shipping addresses, and order information were exposed, increasing the amount of personal data available for targeted phishing, although Trezor's wallet systems and backups were not compromised.

The fake entropy warning also echoes the Coldcard weak-seed failure, which produced more than 1,778 BTC in high-confidence thefts and prompted emergency firmware changes in August. Against that backdrop of real disclosures, a security-themed email is more likely to be taken at face value, which is precisely the credibility this campaign exploited.

Trezor continues to investigate access to its email infrastructure, while BitBox has contacted its newsletter provider and reported the phishing domains. Both companies have used their official subreddits and support pages to publish updates, making those channels the reference point for verified information as the investigations continue.