Hardware wallet manufacturers Trezor and BitBox have issued urgent warnings to their users after a coordinated phishing campaign leveraged a compromised third-party email service provider to distribute fake hardware wallet security alerts. The breach allowed attackers to send fraudulent messages that appeared to originate from legitimate company infrastructure, complicating efforts by recipients to identify the emails as malicious before interacting with them.
BitBox indicated that the campaign affected multiple Bitcoin companies that had been targeted through a shared newsletter provider, according to Cointelegraph. The Swiss hardware wallet maker said the compromise of this common vendor enabled adversaries to reach customers across several firms, pointing to a broad attack against the sector rather than isolated incidents aimed at a single organization. The use of a shared service provider in the cryptocurrency industry can create concentrated points of failure, where a single vendor compromise cascades into security incidents for numerous companies and their combined user bases.
Trezor separately confirmed that its own email service was breached, allowing phishing emails to be sent from the company’s legitimate domain. The Block reported that the third-party security breach facilitated the distribution of the fraudulent alerts, which were designed to mimic official Trezor communications. The use of an authentic domain in a phishing operation can erode standard user defenses that rely on verifying sender addresses, as the emails bypass typical checks for spoofed or suspicious origins and may align visually with genuine marketing or support correspondence.
The email campaign comes on the heels of another third-party lapse affecting Trezor customers. As The Block noted, the incident follows a security breach last month at shipping provider ShipMonk, which exposed the personal information of Trezor customers. That previous compromise involved order fulfillment data rather than communications infrastructure, but it similarly demonstrated the risks introduced by external vendors that handle sensitive operational functions. The recurrence of such breaches within a short timeframe illustrates how hardware wallet providers remain exposed to supply-chain and vendor risks even when their core products are architected to resist remote extraction of private keys.
While the companies did not disclose the exact volume of phishing emails distributed, the acknowledgment of a shared newsletter provider compromise suggests a potentially wide reach across the cryptocurrency hardware industry. Users of such devices generally depend on them to keep private keys offline, making fraudulent security alerts particularly dangerous if they prompt recipients to compromise recovery phrases or interact with malicious interfaces disguised as firmware updates or authentication requests.
The back-to-back incidents involving distinct third-party suppliers highlight the peripheral security challenges facing hardware wallet firms. Even when the physical devices and their embedded software remain uncompromised, the surrounding ecosystem of email marketing platforms and logistics partners presents attack surfaces that can be exploited to harvest data or deceive users. Trezor and BitBox have both moved to notify their communities as the phishing campaign remains active, underscoring the importance of scrutinizing unexpected communications claiming to originate from wallet manufacturers.