Trezor and BitBox issue urgent warnings over fake security alerts

Trezor confirmed a breach at its email provider, prompting immediate user warnings.
Trezor confirmed a breach at its email provider. The company identified a specific phishing email as fraudulent. Recipients were instructed to ignore all links in the message.
BitBox issued a parallel warning on the same day. Preliminary reviews suggest its newsletter provider was compromised. Multiple Bitcoin companies appear to be targeted through this shared service.
Phishing campaign targets shared infrastructure
The fraudulent message mimicked an urgent security notice. It referenced a specific STM32 entropy vulnerability. Trezor explicitly labeled this alert as fake.
BitBox stated its own devices were not directly compromised by this incident. The risk stems from the third-party newsletter platform. Attackers likely exploited the shared provider to reach multiple brands.
Recent data breaches impact customer records
Trezor disclosed a breach at its shipping provider ShipMonk on August 13. This incident exposed data for nearly 14,000 customers. A separate disclosure on September 4 affected 67,000 US customers.
BitBox addressed a vulnerability in Coldcard random-number generation in July. It released an update in August to fix two severe firmware flaws. No known exploitation or stolen funds were reported from these fixes.
Companies decline to comment further
Cointelegraph reached out to both Trezor and BitBox for additional details. Neither company provided a response before publication. The warnings serve as the primary source of information for users.






