Hardware wallet makers Trezor and BitBox warned users this week about phishing emails dressed up as urgent security alerts, after attackers gained access to third-party email services and sent fake warnings from legitimate company channels. Trezor confirmed on Wednesday that its email provider had been breached and told recipients not to touch a message titled “Critical Security Alert: STM32 Entropy Vulnerability.” BitBox reported nearly identical emails reaching its users the same day.
How the scam works
The fake Trezor email claims a factory defect in STM32 microcontrollers weakened recovery-phrase generation on roughly one in four devices, and pushes readers to a “vulnerability check” page. That page is designed to harvest wallet information or the recovery seed itself. The story is convincing because it borrows a real category of hardware concern: entropy flaws in microcontrollers are a known research topic, and a user has no easy way to verify the claim from inside an email.
Trezor said it took down the phishing domain and is investigating how attackers reached its email provider. The company stressed that its hardware wallets, private keys and recovery backups were not affected. Casa’s chief security officer said the messages came from real Trezor servers rather than spoofed addresses, which points to a shared marketing or newsletter platform being compromised. BitBox’s preliminary review reached a similar conclusion: its newsletter provider was likely breached, and several other Bitcoin companies using the same provider appear to have been targeted too. CoinTracking users reported similar emails, suggesting the campaign spread across multiple crypto businesses at once.
Why the seed phrase is the prize
A hardware wallet stores its recovery seed, usually 12 or 24 words, inside a secure element, and the phrase never leaves the device in normal use. No PIN, passphrase or firmware protection matters once a user types the seed into a website controlled by an attacker. That is why phishing campaigns keep chasing the seed rather than the device itself, and why both companies’ warnings focused on one instruction: never enter a recovery phrase on any website.
Neither company has confirmed any stolen funds so far. The campaign follows a run of bad security news for the sector: Trezor disclosed in August that a breach at its shipping provider ShipMonk exposed data belonging to nearly 14,000 customers, and on September 4 it said another 67,000 US customers were affected. BitBox separately patched two firmware flaws in August, one of which could have allowed malicious firmware installation under certain conditions, while the second involved Bitcoin address handling and could have affected address verification.
What users should do
The safest response to any security email is to ignore it entirely and type the company’s address into the browser manually. Anyone who clicked a phishing link but did not enter a seed phrase should clear browser data and watch their wallet addresses for unexpected transactions. Anyone who did enter a seed phrase should treat the wallet as compromised immediately: build a new wallet on a clean device with a fresh seed and move all funds across before the attacker does. If the funds are already gone, the practical options shrink to reporting the theft to local cybercrime authorities and to the wallet maker’s support team.
The episode also puts supply-chain risk back in focus. Attackers no longer need to breach the wallet maker itself; compromising a newsletter vendor that can send email from the company’s own domain gets them nearly the same result. Email authentication systems did not catch the campaign, because the messages were technically legitimate mail from a legitimate sender.
Crypto firms that rely on third-party email platforms now face the same question banks dealt with years ago: a vendor with send access to your customers is part of your attack surface, whatever the contract says. Expect stricter vendor reviews, hardware-key requirements on email accounts and narrower send permissions across the industry in the coming months, because this campaign showed exactly how cheap and effective the trick is.

discussion