Trezor, BitBox Users Hit by Phishing Email Attack

Crypto users have a new reason to be careful with emails that claim to come from trusted wallet companies. Trezor, BitBox and CoinTracking users have been hit by a phishing campaign that used compromised email and newsletter systems to send fake security messages.

The attack is serious because the emails did not always look like normal scam messages. Some were sent through real email systems used by the affected companies. This made the messages appear much more trustworthy and gave attackers a better chance to fool crypto users.

Trezor confirmed that its third-party email provider had been breached. BitBox also reported a similar incident and said several Bitcoin companies appeared to share the same newsletter provider. CoinTracking also warned its users about fake emails. Reports have linked the common email provider to Brevo, the service formerly known as Sendinblue.

A Fake Security Warning

One of the main fake Trezor emails had the subject line “Critical Security Alert: STM32 Entropy Vulnerability.”

The message claimed that a serious security problem had affected STM32 chips used in hardware wallets. It urged users to take action and visit a website for an “entropy check.”

The story sounded technical, which made it more believable. STM32 chips are real components used in some hardware devices. Attackers used that real detail to create a false sense of trust.

The website linked from the email was not a genuine Trezor security tool. Its real purpose was to trick users into giving away sensitive wallet information.

Trezor confirmed that the email was fake and told users not to click its links. The company also said it had taken down the malicious domain and started an investigation into how attackers gained access through its third-party email provider.

BitBox Users Also Targeted

BitBox reported a similar attack around the same time. The Swiss hardware wallet company said several Bitcoin firms appeared to have been targeted through a shared newsletter provider.

This detail matters because it suggests that the attack was not limited to one company. Instead, criminals may have found a weakness at the outside service that handled email delivery for several crypto businesses.

BitBox warned its users not to follow instructions from the fake message. The company also said that most of the harmful links had gone down after the attack came to light, although its investigation was still active.

The attack shows why third-party services can become a major security risk. A company may have strong internal security, but an outside service can still become a path for criminals to reach its customers.

CoinTracking Warns Its Customers

CoinTracking, a crypto portfolio and tax service, also confirmed that fake emails were in circulation.

Its official support page says the messages may lead users to websites that ask for access details to crypto exchanges. CoinTracking says neither the company nor its staff will ask for wallet credentials, exchange credentials, API keys with trading or withdrawal rights, credit card details or other sensitive access information.

CoinTracking also made clear that it does not hold customer funds. So, any message that claims a user has money at CoinTracking that can be released after payment is a scam.

This warning is important because criminals often change their story while keeping the same goal. One message may ask for a wallet seed. Another may ask for exchange details. Both can lead to the loss of crypto.

Why These Emails Looked Real

This case is more serious than a simple fake email from a strange address.

Email security tools often check systems such as SPF, DKIM and DMARC. These systems help confirm whether an email came through an approved sending service and whether its digital signature is valid.

If criminals gain access to a real email provider account, those checks may not stop the message.

That is what makes this type of attack dangerous. The email can come through a service that the real company already uses. As a result, the message may pass technical checks even though its content is false.

A recent report said the emails appeared to use legitimate sending infrastructure connected to the affected companies. This means users could not safely judge the message only by looking at the sender name or email address.

The Real Target Is the Recovery Seed

The main prize for the attackers is a wallet recovery seed.

A recovery seed is usually a list of 12 or 24 words. It acts as the master key for a crypto wallet. A person who has that seed can restore the wallet on another compatible device.

That means a criminal does not need to break the hardware wallet itself.

If a user enters the recovery words into a fake website, the attacker may gain full control of the wallet. The criminal can then create a copy of the wallet and transfer its funds elsewhere.

Trezor has repeatedly warned that no legitimate company will ask for a wallet backup, recovery words, PIN, password or security code. The company says users should treat any such request as a scam.

BitBox gives the same advice. Its support team says it will never ask for recovery words, wallet backups, private keys, passwords, passphrases, PINs or authentication codes.

Never Enter Your Seed on a Website

This is the most important rule for hardware wallet users.

Your recovery seed should never go into a website, email form, online tool or chat service.

A real hardware wallet company has no reason to ask you to type your seed into a web page. If an email tells you that you must “verify,” “check,” “secure” or “restore” your wallet through a link, stop before you do anything.

Do not trust a message simply because it has the correct logo. Do not trust it because the email looks professional. Do not trust it because the sender name looks familiar.

Instead, open a new browser window and visit the company’s official website yourself.

What Users Should Do Now

Anyone who received one of these emails should avoid its links and attachments.

If you only saw the email and did not click anything, there is usually no reason to panic. Delete the message or mark it as spam.

If you clicked the link but did not provide sensitive information, close the page and run a security check on your device. It is also wise to check your wallet and account activity for anything unusual.

The situation is far more serious if you entered your recovery seed.

A seed that has appeared on a fake website should be treated as compromised. The safest response is to create a new wallet with a new seed on a trusted device and move the funds to it. Do not reuse the exposed seed.

Check Software Only Through Official Sources

Users should also be careful with wallet software and firmware updates.

Trezor says legitimate updates should come through Trezor Suite and official Trezor sources. BitBox also tells users to get the BitBoxApp from its official website.

Never install wallet software because an email tells you to do so.

The same rule applies to QR codes. A QR code can hide the real destination, so it should receive the same level of caution as a normal link.

A Lesson for Crypto Users

This attack shows how much trust criminals can exploit.

Many people know that fake crypto emails exist. They know that strange domains and poor grammar can be warning signs. But this campaign shows that even a well-written email from a familiar company can be dangerous.

The bigger lesson is simple: trust the device and official website, not the email.

Trezor, BitBox and CoinTracking did not ask users to reveal their private wallet information. The fake messages tried to create fear and urgency so people would act before they had time to check the facts.

Crypto users should slow down whenever a message claims that funds are at risk or that immediate action is required.

A hardware wallet can protect private keys very well, but it cannot protect a user who willingly gives away the recovery seed.

That is why the recovery phrase must remain private at all times. If an email, website or person asks for it, the safest answer is always the same: do not provide it.

ALSO READ: Operation Big Tuna: Who Gets the $225 Million Crypto?

Leave a Reply

Your email address will not be published. Required fields are marked *