Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Multiple hardware crypto wallet providers warn of phishing emails after third-party incident

Trezor and BitBox are among the companies warning of scam emails after their newsletter provider was allegedly compromised.

Thu, 10 Sep 2026
Multiple hardware crypto wallet providers warn of phishing emails after third-party incident

An unidentified actor has compromised a third-party email provider used by several cryptocurrency firms and used that access to send out phishing emails to their customer base.

BitBox, a Swiss firm that makes hardware crypto wallets, was the first to warn its customers of the malicious messaging.

“There is currently a phishing email going around that’s pretending to come from us,” the company said via an early morning post to X.

 
 

“Please do not follow the instructions in the email!”

BitBox said it was investigating the emails and, soon after, posted an update, confirming the third-party hack.

“Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised,” BitBox said.

According to the company, several other bitcoin companies were impacted, all of which appeared to use the same provider.

“We sent out a phishing warning to all our newsletter subscribers, contacted the provider and reported the phishing domains. Most of the phishing links appear to have been taken down already,” BitBox said.

“We are still actively investigating this situation and will update you once we know more.”

Trezor, which is also in the hardware wallet business, warned its customers at about the same time.

“A third-party email provider used by Trezor was breached and used to send a phishing email titled ‘Critical Security Alert: STM32 Entropy Vulnerability’. The message is not legitimate, and recipients should not click any links,” Trezor said.

“The affected domain has been taken down, and an investigation is underway to determine how the attackers gained access to the legitimate domain.”

The phishing email in question, which Cyber Daily has seen, warned of an alleged “critical hardware-level vulnerability” in the microcontrollers used in the hardware wallet.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: