Trezor and BitBox Hit By Phishing Attack After Shared Email Provider Breach

Two of the biggest names in hardware wallets, Trezor and BitBox, warned customers this week that a breach at a shared third-party email provider let attackers send convincing phishing emails straight to their subscriber lists.
WHAT HAPPENED
Trezor posted the warning first. Trezor confirmed the breach directly: "Our third-party email provider has been breached. Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link." BitBox posted a nearly identical warning the same day. BitBox followed with its own disclosure, saying its preliminary review pointed to the shared newsletter provider as the source.
The two companies were not the only ones affected. Attackers exploited a breach at Brevo, the email marketing and newsletter platform formerly known as Sendinblue, to send fraudulent "Critical Security Alert" emails directly to the subscriber lists of Trezor, BitBox, and CoinTracking. Brevo said in a statement that a security incident had allowed an attacker to access 120 Brevo accounts, and that the bad actor used the access to send phishing emails to the client's contactbase.
The fake emails were built to look official. The emails impersonated legitimate security bulletins, warned recipients of a fabricated "STM32 Entropy Vulnerability," and pointed them to a fake verification tool built to harvest wallet recovery phrases. Making matters worse, the phishing message reached inboxes from Trezor's own real domain rather than a spoofed lookalike, which made it harder than usual for recipients to spot.
THE COLD CARD CONNECTION
On the show, Nico and Opti pointed out that this attack was designed to exploit lingering anxiety from a separate, earlier entropy scare involving Cold Card hardware wallets. The fake alert's framing, a critical chip vulnerability that could expose seed phrases, was chosen specifically because the crypto community had just been primed to worry about exactly that kind of flaw. Attackers appear to be getting more sophisticated about layering social engineering on top of real news cycles rather than inventing threats from nothing.
THE TAKEAWAY
No hardware wallet company has reported confirmed fund losses tied to this specific campaign. No confirmed cryptocurrency losses have been tied to the phishing campaign as of publication. But the incident is at least the second vendor-side failure to touch Trezor customers in recent weeks, following an earlier breach at a shipping partner that exposed customer shipping and contact data.
The rule the hosts kept coming back to is simple and has not changed: never type a seed phrase into anything connected to the internet, no matter how official the email looks or how urgent it sounds. A legitimate hardware wallet company will never ask for a recovery phrase by email. If an alert claims otherwise, the alert is the attack.
This story comes from the Simply Bitcoin Live show. Watch the full episode.



