We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Crypto phishing: why an email from a legitimate domain can still be fake
Crypto phishing can start with an email sent from a company’s legitimate domain. On September 9, 2026, 347,149 subscribers to Trezor’s mailing list received an email with the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” It claimed that a microcontroller flaw could cause the wallet to generate predictable backups and urged users to check their device through a separate app. The attackers sent the emails through Brevo — the same email platform Trezor used for legitimate campaigns — so the messages passed standard email authentication checks and looked genuine. About 2,500 people clicked the malicious link before the phishing domain was blocked. Similar emails reached BitBox subscribers that same day, while CoinTracking users received a message telling them to urgently refresh their API keys.
The usual advice to “check the sender address” was not enough in this case. An email could arrive from an address on Trezor’s legitimate domain and still pass SPF, DKIM, and DMARC because it was sent through a service that Trezor itself had authorized to send email on its behalf. Below, we’ll look at how that happened and what matters more than the From address when an email is about your hardware wallet’s security.
How crypto phishing differs from bank fraud
A mistaken or fraudulent crypto transfer usually cannot be reversed the way a card transaction can sometimes be disputed through a bank. There is no central operator in a blockchain that can simply cancel a confirmed transaction. That means an attacker often does not need to break the wallet or the network itself. It may be enough to convince the owner to reveal a wallet backup, sign a transaction prepared by the attacker, or send funds to the wrong address.
Most attacks of this kind fall into three recurring patterns:
approvetransaction, or, for some tokens, aPermitsignature or another form of authorization. Not every signature lets someone move your assets, but a specific transaction or signed permission can give a smart contract access to your tokens. We cover these mechanisms in more detail in our guide to Approve, Permit, and WalletConnect.The September campaign targeting Trezor and BitBox subscribers used the third approach. The trick itself was familiar, but this time the phishing emails were sent through a real email service used by the companies themselves.
What happened on September 9 and 10, 2026
What the phishing emails said
The Trezor-themed email used the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” It claimed that STM32 microcontrollers had a hardware flaw affecting random-number generation and that, as a result, a wallet backup could supposedly be brute-forced. The link led to a malicious site that prompted users to download an app and enter their wallet backup.
BitBox subscribers received a similar lure with the subject line “Critical Security Alert: Microcontroller Entropy Bug Identified.” CoinTracking also warned users that day about a phishing email titled “Data Breach Notice: Please refresh API Keys as soon as possible,” which directed users to an external page where they were told to update their exchange API keys.
The story sounded plausible because it used real technical concepts. A specific microcontroller name, references to a critical vulnerability, and pressure to act immediately can be convincing — especially when the message arrives through a channel users already associate with the company.
How the attackers gained access to the mailing system
Trezor devices, Trezor Suite, and Trezor’s internal systems were not breached. The problem was on the Brevo side. Brevo, formerly Sendinblue, is an email marketing platform used by Trezor, CoinTracking, and other companies. In its initial notice, BitBox also said the campaign appeared to involve a shared email provider.
In its final incident report, Brevo explained that the issue involved its SAML SSO implementation. The attacker created a Brevo account, enabled SSO, and invited other Brevo users into that configuration. Because of an access-control flaw, signing in through SSO was not properly restricted to the attacker’s own organization, allowing access to other organizations available to the invited users.
Brevo ultimately confirmed that:
Brevo fixed the flaw used in the attack on September 10 at 08:30 UTC, or 10:30 CEST, and then forcibly terminated all active sessions.
The scale of the Trezor campaign
According to Trezor’s updated incident report, the campaign reached 347,149 addresses from its subscriber database. The phishing domain was blocked at the DNS level within 20 minutes, but about 2,500 people had already clicked the link. Trezor stopped sending email through Brevo and stressed that its devices, Trezor Suite, wallets, and other internal systems were not affected.
At first, Trezor could not confirm whether the mailing list itself had been exported. On September 17, the company updated its notice: Brevo had confirmed that all 347,149 email addresses were exported through the API. Those addresses should therefore be treated as known to the attacker and may be used in future, more personalized campaigns.
BitBox also warned subscribers about the fraudulent campaign. Its initial assessment pointed to the email service provider. BitBox did not publish the same level of detail about what specific customer data may have been accessed.
Why the sender address alone is not enough
Checking the sender address still matters because it catches obvious fakes such as
trezorr.io. But even an address on the company’s real domain is not proof that the message is safe if an attacker has gained access to an authorized email platform. That is exactly what happened in the Trezor case: the attacker used Brevo, which Trezor had authorized to send email for its domain.Companies commonly use specialized email platforms for newsletters and other bulk mail. SPF, DKIM, and DMARC help receiving mail systems evaluate those messages:
DMARC does not require both SPF and DKIM to pass. One aligned mechanism is enough. In the Brevo incident, the normal checks did not stop the attack because the phishing emails were being sent through a legitimate email system, so they did not look forged to the receiving mail provider.
SPF, DKIM, and DMARC can confirm that a message came through infrastructure authorized for the domain. They cannot tell whether the company approved that specific message or whether the account inside the email platform was being controlled by an authorized user. If an attacker takes over that access, Gmail or another mail service may see the message as technically legitimate.
That is why, with wallet security emails, the sender address matters less than what the message is asking you to do. If the email claims there is a vulnerability, firmware update, or device problem, verify it separately through the manufacturer’s official website or app instead of following the link in the email.
How data leaks make phishing emails more convincing
A phishing email becomes much more believable when the attacker already knows that you bought a hardware wallet and has your name, email address, phone number, or shipping address. That information may be stored not only by the wallet manufacturer but also by shipping companies, payment providers, and marketing platforms.
Trezor and ShipMonk, August 2026. On August 10, logistics partner ShipMonk notified Trezor of unauthorized access to customer data. For 11,742 customers, the exposed data included name, email, phone number, and shipping address; for another 1,947, it included name, city, and email. In early September, Trezor learned that the incident also affected roughly 67,000 U.S. customers whose records had remained with ShipMonk from an earlier period of cooperation in 2019–2021. After the scope was updated, Trezor said that 80,689 customers had been affected in total.
Trezor had previously received written confirmation from ShipMonk that older data had been deleted, but some records remained. The incident did not affect Trezor devices or systems. In customer notifications cited by industry media, ShipMonk linked the breach to a vulnerability in the Metabase analytics platform. Metabase separately confirmed active exploitation of a zero-day SQL injection issue that could be used to create an administrative session and access data in a vulnerable deployment.
Ledger, July 2020. An attacker obtained access to Ledger’s e-commerce and marketing database through a third-party API key. Ledger initially reported roughly one million email addresses and another 9,500 records containing names, postal addresses, and phone numbers. When the full database was published publicly in December 2020, Ledger updated the scale: names, postal addresses, and phone numbers had been exposed for about 272,000 customers, while more than one million email addresses were affected.
After the leak, Ledger customers were heavily targeted with phishing campaigns, and the publication of home addresses created a very real physical-security concern. In January 2026, Ledger disclosed another customer-order data incident, this time involving payment partner Global-e.
Even when the hardware wallet itself remains technically secure, stolen customer data lets attackers reference your name, device model, or order details. That makes a fake message much harder to recognize at a glance.
Some personal data has to be shared when a physical product is shipped. Still, there is no reason to use the same email address for hardware wallet purchases, exchanges, and public accounts, or to provide extra information when it is not needed. Where possible, choose a delivery method that does not expose your home address to more intermediaries than necessary.
How to tell a legitimate manufacturer email from phishing
What to look for in the email itself
After the September campaign, both Trezor and BitBox repeated the same basic rule: support will not ask for your wallet backup, private keys, PIN, passphrase, passwords, or authentication codes.
Trezor states that it will not ask users to send a wallet backup or take sensitive wallet actions in response to an unexpected email or message. Firmware should be updated through Trezor Suite or another process described in the official documentation, and the app itself should be downloaded only from Trezor’s official website. Compatible devices can also be updated through Trezor Suite on Android, so “desktop only” is no longer a universal rule.
BitBox gives similar guidance: support will not ask for recovery words, a wallet backup, private key, passphrase, PIN, or authentication codes. BitBox02 firmware is installed through BitBoxApp; there is no need to download a separate firmware file for a normal update.
Be especially cautious when an email asks you to enter secret information or take a wallet-related action through a link: “check your wallet for a vulnerability,” download an unfamiliar tool, move funds to a “safe address,” or install an update from a third-party site.
What to check before acting on an email
Official Trezor and BitBox channels
Trezor: the primary domain is trezor.io, support is available through the official support section, and Trezor Suite should be downloaded from Trezor’s own website. Trezor also lists invity.io, vexl.it, tropicsquare.com, and satoshilabs.com as company domains; its official X account is @trezor.
BitBox: official domains include bitbox.swiss, shop.bitbox.swiss, support.bitbox.swiss, blog.bitbox.swiss, and contact.bitbox.swiss. Support also replies from [email protected]. Even so, an address that looks official does not make a request for recovery words or other secrets a legitimate support request.
Spelling or grammar mistakes are no longer a reliable phishing indicator either. Modern phishing emails can be well written in any language, use polished layouts, and include convincing technical terminology.
What to set up in advance
What to do if you already opened the email or entered information
If you received a suspicious email but did nothing. Do not click any links or download attachments. Mark the message as phishing, then verify any claimed vulnerability through the manufacturer’s official website or app.
If you only clicked the link in the September Trezor email but did not enter your wallet backup or run the downloaded file. According to Trezor, clicking the link alone did not give the attacker access to your funds. Close the page and delete the file if it downloaded but you did not run it. This assessment applies to this specific Trezor campaign; other malicious sites may behave differently.
If you entered your wallet backup or seed phrase. Assume the words are already known to someone else and act without delay:
If you ran an unknown app, installed an extension, or gave software access to your computer. Do not create a new wallet backup on that device and do not use it to sign in to exchanges, email, or other important accounts until the system has been checked. Reinstall the operating system from a trusted source if necessary. Change any passwords or keys the software may have accessed from another trusted device.
If you signed a suspicious transaction or permission. Review your transaction history and active token approvals on the relevant network. Revoke dangerous permissions. If you already signed a direct transfer or the assets have been moved, revoking approvals will not bring the funds back.
Phishing and malicious content can be reported to the Cyber Police of Ukraine. Its official website provides a form for reporting cyber incidents, while formal reports can be submitted at cyberpolice.gov.ua/declare. You should also notify the manufacturer through its official support channel so it can help get the phishing domain or malicious file blocked faster.
If your email address was on Trezor’s mailing list. Treat it as potentially known to attackers. The next message may come from a different domain, use a different subject, or include personalized details.
What to remember
Crypto phishing does not always come from an obviously fake address: an email can pass authentication checks and still be malicious. If a message is about wallet security, open the manufacturer’s website or app yourself and verify the information there.
Never send support your wallet backup, private keys, PIN, or passphrase, and never enter them into forms linked from emails. Install updates only through the official app or a process documented by the manufacturer. If your recovery words have already been exposed, do not use them again: move your assets to a new wallet with a new backup.
Related Posts
Dirty Crypto: How To Check If Your Funds Are Clean
Dirty crypto refers to funds whose transaction history is linked to illicit or high-risk activity. According to the Chainalysis Crypto Crime Report 2026, illicit cryptocurrency addresses received at least $154 billion in 2025, up 162% from the previous year. Stablecoins accounted for 84% of that volume: criminals use them for many of the same reasons …
What Is a VPN: Settings, Privacy Rules, and the Best VPN Services in 2026
What is a VPN, and what does it actually do? VPNs have become a familiar privacy tool, but their capabilities are often misunderstood. Some people turn one on only to access a blocked website, others expect complete anonymity, and some install the first free VPN they find and use it for their primary accounts. A …
How Coldcard Was Hacked — and Why a Firmware Update Won’t Fix Your Seed
On July 30, 2026, a series of thefts began from Bitcoin wallets whose seeds had been created on vulnerable versions of Coldcard firmware. During the first major incident, 1,082.65 BTC was drained from 1,196 addresses in just 41 minutes. The attackers did not need physical access to a Coldcard, phishing, or a transaction signed by …
Firmware Update for a Hardware Wallet: When to Update and When to Wait
A hardware wallet firmware update often feels like a minor thing: people buy a hardware wallet so it can sit in a drawer and not cause problems. Most of the time, that is exactly what happens — until the app suddenly says that a firmware update is available. That is where users tend to split …