Wallet Makers Warn Users of Phishing Wave

Attackers exploited a shared email vendor to send fake security alerts to crypto users, prompting urgent warnings from major hardware wallet brands.
Owners of hardware cryptocurrency wallets received alarming emails claiming their devices had critical security flaws. These messages, which appeared to come from trusted brands, urged users to take immediate action to protect their funds. The urgency of the warnings was designed to bypass careful consideration and prompt quick clicks.
Several major manufacturers have now confirmed that these emails were fraudulent. The incident did not stem from a hack of the wallet companies themselves, but rather a breach of a third-party service they used to send newsletters. This vulnerability allowed attackers to impersonate legitimate businesses and reach a large, targeted audience with deceptive content.
Shared vendor breach enabled impersonation
The root of the problem was a compromise at a third-party email provider used by multiple cryptocurrency firms. As reported by GN technics/hardware (en-US), this single point of failure allowed an unidentified actor to access the mailing lists of several companies. By exploiting this access, the attackers could send emails that looked exactly like official communications from these brands.
Swiss wallet maker BitBox was among the first to issue a public warning. The company stated that its preliminary review suggested the newsletter provider had been compromised. They noted that other Bitcoin companies using the same service were also affected. This highlights a common risk in digital operations: relying on external vendors for critical communication channels can create shared vulnerabilities.
Fake alerts targeted device security
The phishing emails used specific technical language to appear credible. One message, which Trezor also identified, claimed there was a critical vulnerability in the microcontrollers used in their hardware wallets. The email titled “Critical Security Alert” warned of a hardware-level flaw that did not exist. This tactic leverages users' fear of losing control over their assets to drive engagement with malicious links.
Trezor advised recipients not to click any links in the message. The company confirmed that the affected domain had been taken down following the report. However, the trade-off in such rapid response scenarios is that users who already acted on the fake alert may have already exposed their credentials or downloaded malware. The speed of the takedown helps stop further spread but does not undo the damage to those who clicked first.
Users must verify communication sources
In the wake of this incident, security experts recommend that users treat any email urging immediate action with skepticism. Legitimate companies rarely send unsolicited, urgent security alerts via email without prior context. If an email claims a critical vulnerability, the safest response is to navigate directly to the company’s official website through a browser, rather than following links in the message.
This incident serves as a reminder that supply chain security is a significant part of personal digital safety. Even if a primary service is secure, the tools and partners it uses can introduce risks. For wallet holders, the catch is that trust is often blind; verifying the source of every communication is a necessary, if tedious, step to maintaining security.






