Hardware wallet makers say attackers used compromised email infrastructure to send phishing messages to crypto holders.
Trezor and BitBox, two well-known makers of cryptocurrency hardware wallets, have issued warnings to customers about fake security alerts. The companies say the messages are designed to look like legitimate communications from the manufacturers themselves.
Trezor confirmed that hackers gained access to its email service provider. That breach allowed attackers to send phishing emails through infrastructure tied to the company's name, according to the firm. The exact scope of the intrusion, including how many customer email addresses were exposed, has not been detailed.
BitBox issued a similar warning around the same time, alerting its own user base to fraudulent security notices. It remains unclear whether the two incidents are directly connected or represent separate phishing campaigns aimed at hardware wallet users more broadly.
Phishing attacks against hardware wallet customers typically try to trick users into entering their recovery seed phrase on a fake website or device interface. Hardware wallets are designed to keep private keys offline, away from internet-connected devices. That security model only holds if users avoid sharing their seed phrase, a string of words that can fully restore access to a wallet, with anyone or any website.
Attackers who compromise an email provider used by a trusted brand can send messages that appear to come from an official support channel. This makes the fraudulent alerts harder for recipients to identify as fake. Trezor and BitBox both urged customers to treat unsolicited security warnings with caution and to verify any communication through official channels before taking action.
Neither company has said that customer funds or devices were directly compromised as a result of the email breach. The warnings focus on the phishing emails themselves rather than any confirmed loss of assets. Users of both wallets have been advised to double-check sender addresses and avoid clicking links in unexpected security notices.
Phishing campaigns targeting hardware wallet users tend to raise broader concerns about supply-chain and vendor-side security risks in the crypto custody sector. Even when a breach is limited to email infrastructure rather than wallet firmware or private keys, incidents like this can shake user confidence in the communication channels companies rely on to reach customers.
For the wider hardware wallet market, such incidents typically prompt renewed emphasis on user education around seed phrase security and phishing recognition. They do not, based on what has been reported, indicate a flaw in the underlying hardware security model that keeps private keys offline.
Trezor and BitBox's warnings underscore that email-based phishing remains a persistent threat even for security-focused hardware wallet providers. Users are advised to verify communications through official company channels and never share recovery phrases in response to unsolicited alerts.
Trezor said hackers breached its email service provider, which attackers then used to send phishing messages to crypto users.
Neither Trezor nor BitBox has reported confirmed loss of funds. The warnings concern fraudulent email alerts, not a breach of wallet hardware or private keys.
BitBox warned its users about similar fake security alerts, though it is unclear whether its incident is directly linked to the Trezor email breach.
Users should verify any security alert through official company channels, avoid clicking links in unsolicited emails, and never share their wallet recovery seed phrase with anyone.
Robinhood’s Tenev Rejects AMC’s Bid to Veto Stock Tokens
Trezor Warns of Phishing Emails Sent From Its Own Domain After Third-Party Breach
Joseph Lubin to Lead MetaMask as Consensys Spins Off Protocol Business
September 10, 2026
September 10, 2026
September 10, 2026
September 10, 2026
September 10, 2026
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect