Written by Ezra Reguerrastaff writerReviewed by Yohan Yunstaff editor
Written by Ezra Reguerrastaff writer
Reviewed by Yohan Yunstaff editor
Trezor, BitBox warn users about fake hardware wallet security alerts
Latest NewsPublishedSep 10, 2026
BitBox stated multiple Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor verified a breach at its email service.

Hardware wallet makers Trezor and BitBox warned users about phishing emails disguised as urgent security notices after suspected compromises involving third-party email services.
On Wednesday, Trezor stated its email provider had been breached and warned that a message titled “Critical Security Alert: STM32 Entropy Vulnerability” was fraudulent. The company urged recipients not to click any links.
On the same day, Bitbox warned users about a phishing email pretending to come from the company. The company stated its preliminary review indicated that its newsletter provider was likely compromised, adding that multiple Bitcoin companies appeared to have been targeted through a shared provider.
The warnings come after several recent security disclosures across the hardware-wallet sector. On Aug. 13, a breach at Trezor shipping provider ShipMonk exposed data belonging to nearly 14,000 customers. On Sept. 4, Trezor disclosed that another 67,000 US customers were affected.
In July, BitBox stated its devices were unaffected by a vulnerability involving Coldcard’s random-number generation. In August, it released an update fixing two severe firmware vulnerabilities, with no known exploitation or stolen funds reported.
Cointelegraph reached out to Trezor and BitBox for more information but did not receive responses before publication.
Related: Cronos confirms $9.2M slipped away before Tectonic exploit rollback


Subscribe to daily byte-sized crypto news from Cointelegraph
Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
- Security
- Cybersecurity
- Hackers
- Blockchain
More on the subject
Uzbekistan begins government bond-backed stablecoin payment pilot
Sep 8, 2026
Ezra Reguerra
Cronos confirms $9.2M slipped away before Tectonic exploit rollback
Sep 8, 2026
Ezra Reguerra
Harmony proposes shutting down layer 1, migrating ONE to Ethereum
Sep 7, 2026
Ezra Reguerra
Uzbekistan begins government bond-backed stablecoin payment pilot
Sep 8, 2026
Ezra Reguerra
Cronos confirms $9.2M slipped away before Tectonic exploit rollback
Sep 8, 2026
Ezra Reguerra
Harmony proposes shutting down layer 1, migrating ONE to Ethereum
Sep 7, 2026
Ezra Reguerra