{"id":72610,"date":"2026-09-18T00:51:27","date_gmt":"2026-09-17T21:51:27","guid":{"rendered":"https:\/\/lwallet.com.ua\/?p=72610"},"modified":"2026-09-18T00:51:27","modified_gmt":"2026-09-17T21:51:27","slug":"crypto-phishing","status":"publish","type":"post","link":"https:\/\/lwallet.com.ua\/en\/crypto-phishing\/","title":{"rendered":"Crypto phishing: why an email from a legitimate domain can still be fake"},"content":{"rendered":"\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Crypto phishing can start with an email sent from a company\u2019s legitimate domain.<\/strong> On September 9, 2026, <strong>347,149 subscribers to Trezor\u2019s mailing list<\/strong> received an email with the subject line \u201cCritical Security Alert: STM32 Entropy Vulnerability.\u201d It claimed that a microcontroller flaw could cause the wallet to generate predictable backups and urged users to check their device through a separate app. The attackers sent the emails through Brevo \u2014 the same email platform Trezor used for legitimate campaigns \u2014 so the messages passed standard email authentication checks and looked genuine. About <strong>2,500 people<\/strong> clicked the malicious link before the phishing domain was blocked. Similar emails reached BitBox subscribers that same day, while CoinTracking users received a message telling them to urgently refresh their API keys.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The usual advice to \u201ccheck the sender address\u201d was not enough in this case. An email could arrive <strong>from an address on Trezor\u2019s legitimate domain and still pass SPF, DKIM, and DMARC<\/strong> because it was sent through a service that Trezor itself had authorized to send email on its behalf. Below, we\u2019ll look at how that happened and what matters more than the From address when an email is about your hardware wallet\u2019s security.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">How crypto phishing differs from bank fraud<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic2-1024x573.jpg\" alt=\"Crypto phishing compared with bank payments and irreversible crypto transactions\" class=\"wp-image-72587\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic2-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic2-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic2-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic2-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic2-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic2-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic2.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A mistaken or fraudulent crypto transfer usually cannot be reversed the way a card transaction can sometimes be disputed through a bank. There is no central operator in a blockchain that can simply cancel a confirmed transaction. That means an attacker often does not need to break the wallet or the network itself. It may be enough to convince the owner to <strong>reveal a wallet backup, sign a transaction prepared by the attacker, or send funds to the wrong address<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Most attacks of this kind fall into three recurring patterns:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>Recipient address substitution.<\/strong> Malware can replace an address in the clipboard. Another variation is address poisoning: an attacker sends a tiny transaction from an address that visually resembles one you already know, hoping you will later copy it from your transaction history.<\/li>\r\n\r\n\r\n\r\n<li><strong>A malicious transaction or dApp permission.<\/strong> A phishing site can prepare a transfer, an <code>approve<\/code> transaction, or, for some tokens, a <code>Permit<\/code> signature or another form of authorization. Not every signature lets someone move your assets, but a specific transaction or signed permission can give a smart contract access to your tokens. We cover these mechanisms in more detail in our guide to <a href=\"https:\/\/lwallet.com.ua\/en\/approve-permit-walletconnect\/\">Approve, Permit, and WalletConnect<\/a>.<\/li>\r\n\r\n\r\n\r\n<li><strong>Stealing the wallet backup.<\/strong> The victim is tricked into entering recovery words on a website or in an app. With the full backup, an attacker can restore the same wallet on another device and control the funds.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The September campaign targeting Trezor and BitBox subscribers used the third approach. The trick itself was familiar, but this time <strong>the phishing emails were sent through a real email service used by the companies themselves<\/strong>.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What happened on September 9 and 10, 2026<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic3-1024x573.jpg\" alt=\"Trezor phishing email about a Critical Security Alert in September 2026\" class=\"wp-image-72590\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic3-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic3-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic3-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic3-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic3-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic3-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic3.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">What the phishing emails said<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The Trezor-themed email used the subject line \u201cCritical Security Alert: STM32 Entropy Vulnerability.\u201d It claimed that STM32 microcontrollers had a hardware flaw affecting random-number generation and that, as a result, a wallet backup could supposedly be brute-forced. The link led to a malicious site that prompted users to download an app and enter their wallet backup.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">BitBox subscribers received a similar lure with the subject line \u201cCritical Security Alert: Microcontroller Entropy Bug Identified.\u201d CoinTracking also warned users that day about a phishing email titled \u201cData Breach Notice: Please refresh API Keys as soon as possible,\u201d which directed users to an external page where they were told to update their exchange API keys.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The story sounded plausible because it used real technical concepts. A specific microcontroller name, references to a critical vulnerability, and pressure to act immediately can be convincing \u2014 especially when the message arrives through a channel users already associate with the company.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">How the attackers gained access to the mailing system<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Trezor devices, Trezor Suite, and Trezor\u2019s internal systems were not breached.<\/strong> The problem was on the Brevo side. Brevo, formerly Sendinblue, is an email marketing platform used by Trezor, CoinTracking, and other companies. In its initial notice, BitBox also said the campaign appeared to involve a shared email provider.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In its <a href=\"https:\/\/status.brevo.com\/incidents\/01M266V1CZKJQNGZRNEGFD5CQE\/write-up\" target=\"_blank\" rel=\"noopener nofollow\">final incident report<\/a>, Brevo explained that the issue involved its SAML SSO implementation. The attacker created a Brevo account, enabled SSO, and invited other Brevo users into that configuration. Because of an access-control flaw, signing in through SSO was not properly restricted to the attacker\u2019s own organization, allowing access to other organizations available to the invited users.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Brevo ultimately confirmed that:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>138 customer accounts<\/strong> were accessed;<\/li>\r\n\r\n\r\n\r\n<li><strong>6 accounts<\/strong> were used to send phishing campaigns;<\/li>\r\n\r\n\r\n\r\n<li>contacts were exported from <strong>43 accounts<\/strong>;<\/li>\r\n\r\n\r\n\r\n<li>Brevo found no significant attacker activity in <strong>93 accounts<\/strong>.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Brevo fixed the flaw used in the attack on <strong>September 10 at 08:30 UTC, or 10:30 CEST<\/strong>, and then forcibly terminated all active sessions.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">The scale of the Trezor campaign<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">According to <a href=\"https:\/\/trezor.io\/blog\/news\/security-incident-at-brevo-our-third-party-email-provider\" target=\"_blank\" rel=\"noopener nofollow\">Trezor\u2019s updated incident report<\/a>, the campaign reached <strong>347,149 addresses<\/strong> from its subscriber database. The phishing domain was blocked at the DNS level within <strong>20 minutes<\/strong>, but about <strong>2,500 people<\/strong> had already clicked the link. Trezor stopped sending email through Brevo and stressed that its devices, Trezor Suite, wallets, and other internal systems were not affected.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">At first, Trezor could not confirm whether the mailing list itself had been exported. <strong>On September 17, the company updated its notice: Brevo had confirmed that all 347,149 email addresses were exported through the API.<\/strong> Those addresses should therefore be treated as known to the attacker and may be used in future, more personalized campaigns.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">BitBox also warned subscribers about the fraudulent campaign. Its initial assessment pointed to the email service provider. BitBox did not publish the same level of detail about what specific customer data may have been accessed.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If you entered your wallet backup or seed phrase into an app or form linked from one of these emails, <strong>assume those words are already known to someone else<\/strong>, even if the funds are still there. On a trusted device, create a new wallet with a new backup and move your assets to new addresses. Do not use the old recovery words again.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">[\/vc_message]<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Why the sender address alone is not enough<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic4-1024x573.jpg\" alt=\"Phishing email from a legitimate domain after SPF DKIM and DMARC checks\" class=\"wp-image-72593\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic4-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic4-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic4-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic4-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic4-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic4-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic4.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Checking the sender address still matters because it catches obvious fakes such as <code>trezorr.io<\/code>. But even an address on the company\u2019s real domain is not proof that the message is safe if an attacker has gained access to an authorized email platform. That is exactly what happened in the Trezor case: the attacker used Brevo, which Trezor had authorized to send email for its domain.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Companies commonly use specialized email platforms for newsletters and other bulk mail. SPF, DKIM, and DMARC help receiving mail systems evaluate those messages:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>SPF<\/strong> specifies which mail servers are allowed to send mail for a domain.<\/li>\r\n\r\n\r\n\r\n<li><strong>DKIM<\/strong> adds a cryptographic signature to the message, which the receiving mail system verifies against a public key published in DNS.<\/li>\r\n\r\n\r\n\r\n<li><strong>DMARC<\/strong> checks whether the domain shown in the visible From field aligns with a domain that passed SPF or DKIM and defines how failed messages should be handled.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">DMARC does not require both SPF and DKIM to pass. One aligned mechanism is enough. In the Brevo incident, the normal checks did not stop the attack because <strong>the phishing emails were being sent through a legitimate email system, so they did not look forged to the receiving mail provider<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">SPF, DKIM, and DMARC can confirm that a message came through infrastructure authorized for the domain. They cannot tell whether the company approved that specific message or whether the account inside the email platform was being controlled by an authorized user. If an attacker takes over that access, Gmail or another mail service may see the message as technically legitimate.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That is why, with wallet security emails, the sender address matters less than <strong>what the message is asking you to do<\/strong>. If the email claims there is a vulnerability, firmware update, or device problem, verify it separately through the manufacturer\u2019s official website or app instead of following the link in the email.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">How data leaks make phishing emails more convincing<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic5-1024x573.jpg\" alt=\"Leaked hardware wallet customer data used in a personalized phishing email\" class=\"wp-image-72596\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic5-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic5-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic5-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic5-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic5-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic5-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic5.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A phishing email becomes much more believable when the attacker already knows that you bought a hardware wallet and has your name, email address, phone number, or shipping address. That information may be stored not only by the wallet manufacturer but also by shipping companies, payment providers, and marketing platforms.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Trezor and ShipMonk, August 2026.<\/strong> On August 10, logistics partner ShipMonk notified Trezor of unauthorized access to customer data. For <strong>11,742 customers<\/strong>, the exposed data included name, email, phone number, and shipping address; for another <strong>1,947<\/strong>, it included name, city, and email. In early September, Trezor learned that the incident also affected roughly 67,000 U.S. customers whose records had remained with ShipMonk from an earlier period of cooperation in 2019\u20132021. After the scope was updated, Trezor said that <strong>80,689 customers<\/strong> had been affected in total.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Trezor had previously received written confirmation from ShipMonk that older data had been deleted, but some records remained. The incident did not affect Trezor devices or systems. In customer notifications cited by industry media, ShipMonk linked the breach to a vulnerability in the Metabase analytics platform. Metabase separately confirmed active exploitation of a zero-day SQL injection issue that could be used to create an administrative session and access data in a vulnerable deployment.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Ledger, July 2020.<\/strong> An attacker obtained access to Ledger\u2019s e-commerce and marketing database through a third-party API key. Ledger initially reported roughly one million email addresses and another 9,500 records containing names, postal addresses, and phone numbers. When the full database was published publicly in December 2020, Ledger updated the scale: names, postal addresses, and phone numbers had been exposed for about <strong>272,000 customers<\/strong>, while more than one million email addresses were affected.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">After the leak, Ledger customers were heavily targeted with phishing campaigns, and the publication of home addresses created a very real physical-security concern. In January 2026, Ledger disclosed another customer-order data incident, this time involving payment partner Global-e.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Even when the hardware wallet itself remains technically secure, stolen customer data lets attackers reference your name, device model, or order details. That makes a fake message much harder to recognize at a glance.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Some personal data has to be shared when a physical product is shipped. Still, there is no reason to use the same email address for hardware wallet purchases, exchanges, and public accounts, or to provide extra information when it is not needed. Where possible, choose a delivery method that does not expose your home address to more intermediaries than necessary.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A leaked shipping address is more serious than another wave of spam. If a database also shows that the person at that address owns a hardware wallet, the issue extends to physical security. <strong>Do not publicly disclose the size of your holdings<\/strong>, avoid showing your devices on social media without a reason, and do not tell people how much cryptocurrency you keep.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">[\/vc_message]<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">How to tell a legitimate manufacturer email from phishing<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic6-1024x573.jpg\" alt=\"How to distinguish a legitimate hardware wallet email from phishing\" class=\"wp-image-72599\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic6-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic6-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic6-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic6-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic6-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic6-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic6.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">What to look for in the email itself<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">After the September campaign, both Trezor and BitBox repeated the same basic rule: <strong>support will not ask for your wallet backup, private keys, PIN, passphrase, passwords, or authentication codes<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Trezor states that it will not ask users to send a wallet backup or take sensitive wallet actions in response to an unexpected email or message. Firmware should be updated through Trezor Suite or another process described in the official documentation, and the app itself should be downloaded only from Trezor\u2019s official website. Compatible devices can also be updated through Trezor Suite on Android, so \u201cdesktop only\u201d is no longer a universal rule.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">BitBox gives similar guidance: support will not ask for recovery words, a wallet backup, private key, passphrase, PIN, or authentication codes. BitBox02 firmware is installed through BitBoxApp; there is no need to download a separate firmware file for a normal update.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Be especially cautious when an email asks you to <strong>enter secret information or take a wallet-related action through a link<\/strong>: \u201ccheck your wallet for a vulnerability,\u201d download an unfamiliar tool, move funds to a \u201csafe address,\u201d or install an update from a third-party site.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">What to check before acting on an email<\/h3>\r\n\r\n\r\n\r\n<ol class=\"nm-block-list wp-block-list\">\r\n<li><strong>Do not take wallet actions through a link in the email.<\/strong> Open the manufacturer\u2019s website manually or from a trusted bookmark. If there is a real vulnerability or urgent update, there should be a matching notice in the official blog, support center, or app.<\/li>\r\n\r\n\r\n\r\n<li><strong>Verify the news independently.<\/strong> During the September incident, Trezor and BitBox quickly published phishing warnings. Open the manufacturer\u2019s site, blog, or app yourself rather than using the link in the message.<\/li>\r\n\r\n\r\n\r\n<li><strong>Update firmware only through the process documented by the manufacturer.<\/strong> Trezor Suite and BitBoxApp notify users when firmware updates are available. A normal update does not require you to enter your wallet backup on a website or into an unrelated third-party app.<\/li>\r\n\r\n\r\n\r\n<li><strong>Do not treat urgency as proof that a message is real.<\/strong> Phrases such as \u201ccritical vulnerability,\u201d a specific chip name, or a 24-hour deadline can all be part of social engineering.<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Official Trezor and BitBox channels<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Trezor:<\/strong> the primary domain is trezor.io, support is available through the official support section, and Trezor Suite should be downloaded from Trezor\u2019s own website. Trezor also lists invity.io, vexl.it, tropicsquare.com, and satoshilabs.com as company domains; its official X account is @trezor.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>BitBox:<\/strong> official domains include bitbox.swiss, shop.bitbox.swiss, support.bitbox.swiss, blog.bitbox.swiss, and contact.bitbox.swiss. Support also replies from support@mail.bitbox.swiss. Even so, an address that looks official does not make a request for recovery words or other secrets a legitimate support request.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Spelling or grammar mistakes are no longer a reliable phishing indicator either. Modern phishing emails can be well written in any language, use polished layouts, and include convincing technical terminology.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">What to set up in advance<\/h3>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>Use a separate email address for hardware wallet purchases.<\/strong> Do not use it for exchanges or public accounts. If a \u201curgent exchange security alert\u201d suddenly arrives at an address you never gave that exchange, that is an immediate warning sign.<\/li>\r\n\r\n\r\n\r\n<li><strong>Use a passphrase only if you understand exactly how it works.<\/strong> In BIP39-compatible wallets, a passphrase is an additional secret that, together with the mnemonic or wallet backup, opens a different wallet. Even a one-character difference produces a different set of addresses. If you lose the exact passphrase, the manufacturer cannot recover it for you. It can reduce the impact of a leaked wallet backup, but it does not replace proper backup security.<\/li>\r\n\r\n\r\n\r\n<li><strong>Do not store recovery words in photos, cloud storage, or notes.<\/strong> Do not photograph them, save them in a password manager, or enter them into web forms. BitBox02, for example, supports backups to microSD as a built-in backup method. That is not the same as keeping a seed phrase photo or text file in ordinary cloud storage.<\/li>\r\n\r\n\r\n\r\n<li><strong>Keep your dApp wallet separate from your main savings.<\/strong> For new DeFi services, mints, or airdrops, use separate addresses with limited balances rather than the wallet that holds most of your funds.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What to do if you already opened the email or entered information<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic7-1024x573.jpg\" alt=\"What to do after crypto phishing: create a new wallet move assets and revoke approvals\" class=\"wp-image-72602\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic7-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic7-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic7-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic7-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic7-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic7-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-crypto-phishing-18-09-2026-content-pic7.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>If you received a suspicious email but did nothing.<\/strong> Do not click any links or download attachments. Mark the message as phishing, then verify any claimed vulnerability through the manufacturer\u2019s official website or app.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>If you only clicked the link in the September Trezor email but did not enter your wallet backup or run the downloaded file.<\/strong> According to Trezor, clicking the link alone did not give the attacker access to your funds. Close the page and delete the file if it downloaded but you did not run it. This assessment applies to this specific Trezor campaign; other malicious sites may behave differently.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>If you entered your wallet backup or seed phrase.<\/strong> Assume the words are already known to someone else and act without delay:<\/p>\r\n\r\n\r\n\r\n<ol class=\"nm-block-list wp-block-list\">\r\n<li>On a trusted device, create a <strong>new wallet with a new backup<\/strong>. Do not restore it from the old recovery words.<\/li>\r\n\r\n\r\n\r\n<li>Move your assets to new addresses and check <strong>every network and token<\/strong> you have used.<\/li>\r\n\r\n\r\n\r\n<li><strong>Do not use the old backup again<\/strong>, even for small amounts.<\/li>\r\n\r\n\r\n\r\n<li>After moving the funds, check whether any assets or active smart-contract approvals remain on the old addresses.<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>If you ran an unknown app, installed an extension, or gave software access to your computer.<\/strong> Do not create a new wallet backup on that device and do not use it to sign in to exchanges, email, or other important accounts until the system has been checked. Reinstall the operating system from a trusted source if necessary. Change any passwords or keys the software may have accessed from another trusted device.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>If you signed a suspicious transaction or permission.<\/strong> Review your transaction history and active token approvals on the relevant network. Revoke dangerous permissions. If you already signed a direct transfer or the assets have been moved, revoking approvals will not bring the funds back.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Phishing and malicious content can be reported to the Cyber Police of Ukraine. Its official website provides a form for reporting cyber incidents, while formal reports can be submitted at cyberpolice.gov.ua\/declare. You should also notify the manufacturer through its official support channel so it can help get the phishing domain or malicious file blocked faster.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>If your email address was on Trezor\u2019s mailing list.<\/strong> Treat it as potentially known to attackers. The next message may come from a different domain, use a different subject, or include personalized details.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">After losing funds, do not search social media or ads for random \u201ccrypto recovery services.\u201d <strong>Phishing victims are often targeted a second time<\/strong> by scammers who promise to recover assets for an upfront payment or ask for access to the wallet.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">[\/vc_message]<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What to remember<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Crypto phishing does not always come from an obviously fake address:<\/strong> an email can pass authentication checks and still be malicious. If a message is about wallet security, open the manufacturer\u2019s website or app yourself and verify the information there.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>Never send support your wallet backup, private keys, PIN, or passphrase, and never enter them into forms linked from emails.<\/strong> Install updates only through the official app or a process documented by the manufacturer. If your recovery words have already been exposed, do not use them again: move your assets to a new wallet with a new backup.<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>Crypto phishing can start with an email sent from a company\u2019s legitimate domain. On September 9, 2026, 347,149 subscribers to Trezor\u2019s mailing list received an email with the subject line \u201cCritical Security Alert: STM32 Entropy Vulnerability.\u201d It claimed that a microcontroller flaw could cause the wallet to generate predictable backups and urged users to check &hellip;<\/p>\n","protected":false},"author":10,"featured_media":72585,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2725],"tags":[],"class_list":["post-72610","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/72610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/comments?post=72610"}],"version-history":[{"count":2,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/72610\/revisions"}],"predecessor-version":[{"id":72612,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/72610\/revisions\/72612"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media\/72585"}],"wp:attachment":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media?parent=72610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/categories?post=72610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/tags?post=72610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}