Hardware wallet makers Trezor and BitBox are warning customers about phishing emails disguised as urgent security notices, sent after suspected breaches of the third-party services that deliver their email.

On Wednesday, Trezor said its email provider had been breached and that a message titled "Critical Security Alert: STM32 Entropy Vulnerability" was fraudulent, urging recipients not to click any links. BitBox separately warned of a phishing email impersonating the company, adding that its preliminary review indicated its newsletter provider was likely compromised and that multiple Bitcoin companies appeared to have been targeted through a shared provider.

What the Fake Alert Claimed

The fraudulent Trezor email claimed the company's engineers had discovered a "critical hardware-level vulnerability" in STM32 microcontrollers used in its devices, and that the defect affected an estimated one in four devices, potentially leaving recovery phrases generated with insufficient randomness — or entropy.

No such advisory exists. Trezor issued no STM32 security notice, and both companies confirmed the emails were phishing attempts.

The claims appear engineered to exploit lingering fear from the Coldcard incident, in which a firmware flaw in the random-number generator allowed attackers to brute-force wallet seeds offline, with roughly $130 million reported stolen to date. Neither Trezor nor BitBox devices were affected by that flaw.

Why the Emails Looked Real

The messages did not need to spoof anything. Security researchers noted the phishing emails were sent from legitimate addresses on the companies' actual sender infrastructure, meaning standard email-authentication checks would not have flagged them.

"It's likely that a marketing email provider was compromised," Casa co-founder and CEO Nick Neuman wrote on X, adding that BitBox users had reported receiving similar messages. Casa Chief Security Officer Jameson Lopp said the emails "don't appear to be spoofed" and stressed that no security advisory had been issued.

Trezor said it took down the domain used in the attack and is investigating how the attackers gained access to its legitimate sending infrastructure.

A Pattern of Third-Party Exposure

The campaign is the latest in a series of incidents in which the security perimeter around hardware wallet vendors — rather than their devices — has been breached.

In mid-August, a breach at Trezor's shipping provider, ShipMonk, exposed data belonging to roughly 14,000 customers. A September 4 disclosure added approximately 67,000 US customers, bringing the combined total to about 80,700 people whose names, email addresses, phone numbers and shipping addresses were exposed. Trezor warned at the time that the leaked data could enable more convincing phishing attempts — a prediction this week's campaign bears out, since attackers now hold verified lists of confirmed hardware wallet owners.

In August, Trezor and Foundation also warned of a phishing surge exploiting public fear of the Coldcard vulnerabilities. BitBox, for its part, said in July its devices were unaffected by the Coldcard RNG flaw, and in August it shipped a firmware update fixing two severe vulnerabilities of its own, with no known exploitation.

The Takeaway

Nothing in this incident points to a flaw in Trezor or BitBox hardware. The devices, keys and seed generation were not touched. What failed is the channel companies use to talk to their customers — and an email from a real vendor address is no longer evidence that a message is genuine.

Users should treat any unsolicited security alert that pushes them to act quickly — follow a link, enter a recovery phrase, or "verify" a device — as hostile, and verify advisories only through the vendor's official website or support channels.

TrustGrade covers the security and trust ecosystem around digital assets. For verified trust data on the platforms and firms shaping it, see trustgrade.ai.