• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Phishing scam

Trezor, BitBox and CoinTracking warn of phishing campaign tied to shared email provider breach

09/11/2026
Russians Indicted For Crypto Laundering: U.S. Charges Trio for Operating Illicit Crypto Mixers

UK’s economic crime centre ranks crypto third-biggest threat, behind only lawyers and politically exposed persons

09/11/2026
Bitcoin ATM scams cost Americans $333 million in first 11 months of 2025, FBI reports

Albuquerque bans crypto ATMs citywide to fight scams targeting seniors

09/10/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Phishing scam

Trezor, BitBox and CoinTracking warn of phishing campaign tied to shared email provider breach

09/11/2026
Russians Indicted For Crypto Laundering: U.S. Charges Trio for Operating Illicit Crypto Mixers

UK’s economic crime centre ranks crypto third-biggest threat, behind only lawyers and politically exposed persons

09/11/2026
Bitcoin ATM scams cost Americans $333 million in first 11 months of 2025, FBI reports

Albuquerque bans crypto ATMs citywide to fight scams targeting seniors

09/10/2026
Friday, September 11, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Breaking News

Trezor, BitBox and CoinTracking warn of phishing campaign tied to shared email provider breach

A coordinated-looking email attack is exploiting trusted crypto brands and urgent security warnings to lure users into handing over sensitive wallet or account information.

by Elizabeth Omotoke
29 minutes ago
in Breaking News
Reading Time: 4 mins read
0
Phishing scam

Phishing scam

Share on FacebookShare on Twitter

Trezor, BitBox and CoinTracking warned customers on September 9 and 10 about a phishing campaign that used compromised email infrastructure to send fraudulent security alerts appearing to come from the companies themselves, an attack BitBox said may have exploited a newsletter provider shared across multiple Bitcoin businesses.

Trezor warned customers not to interact with an email titled “Critical Security Alert: STM32 Entropy Vulnerability.” The company said the message was fraudulent and instructed recipients not to click its links. Trezor also confirmed that its third-party email provider had been breached and said it was investigating how attackers obtained access to its legitimate domain.

Trezor warns of fake hardware wallet emergency

The attackers built the campaign around a convincing technical story: a supposed vulnerability affecting STM32 microcontrollers used in hardware wallets.

The message was crafted to create immediate fear by suggesting that users’ wallet security and recovery phrases were at risk. That type of urgency is a familiar hallmark of a phishing scam, but the campaign’s use of legitimate-looking sending infrastructure makes the deception more sophisticated.

Trezor publicly rejected the warning and said the email did not originate from the company. It also said the malicious domain involved in the campaign had been taken down while its investigation continued.

Trezor’s warning is especially significant because hardware-wallet users are trained to treat security alerts seriously. A message claiming that a wallet’s underlying hardware has developed a critical vulnerability can therefore create exactly the panic an attacker needs to push a victim toward a fraudulent website.

The company has not publicly disclosed how many users received the malicious email or provided evidence that Trezor devices themselves were compromised. Current reporting indicates the incident centered on the company’s email provider rather than the hardware wallets.

BitBox finds evidence of a broader campaign

BitBox’s response suggested the incident could be considerably larger than a single compromised mailing list.

The hardware-wallet manufacturer said its preliminary investigation indicated that its newsletter provider was likely compromised after customers received a fraudulent message. More importantly, BitBox said several other Bitcoin companies had also been targeted and appeared to use the same newsletter provider.

BitBox responded by warning subscribers, contacting its provider and reporting malicious domains. The company said most of the phishing links appeared to have been taken offline, although its investigation remained active.

The development changes the nature of the incident. Rather than an attacker simply impersonating individual crypto brands, the evidence points toward a possible compromise of shared marketing infrastructure capable of reaching customers belonging to multiple companies.

That creates a potentially wider exposure window. If attackers obtained access to mailing accounts or customer lists through a common service, other cryptocurrency companies using the same infrastructure could also become targets.

The campaign demonstrates why a sophisticated phishing scam no longer necessarily requires an obviously fake sender address. Compromising a trusted service provider can give attackers a much more credible delivery channel.

CoinTracking links Its incident to Brevo

CoinTracking, a cryptocurrency portfolio tracking and tax platform, provided another important piece of information about the campaign.

The company warned customers about a fraudulent email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” The message attempted to convince recipients that they needed to take urgent action following an alleged data breach.

CoinTracking identified its third-party email provider as Brevo, adding another data point to the emerging picture of a shared email-service compromise. However, reporting around the wider incident continued to develop, and not every affected company had independently confirmed the same provider publicly at the time of publication.

The fake CoinTracking message is particularly dangerous because API credentials can provide access to cryptocurrency exchange accounts depending on how they are configured. CoinTracking’s own security guidance says users should grant its service only read-only API permissions and never provide trading or withdrawal permissions.

The fraudulent message therefore exploits a legitimate security concern and turns it into an attack vector, a classic tactic in a phishing scam.

Recent data leaks add to crypto users’ exposure

The latest campaign comes at an uncomfortable time for hardware-wallet customers.

Trezor disclosed in August that a breach involving its shipping provider, ShipMonk, exposed customer information. The company later updated its disclosure to say approximately 67,000 additional U.S. customers were affected, with exposed information including names, email addresses, phone numbers and shipping addresses. Trezor stressed that its own systems and devices were not compromised, but warned that the leaked information could increase the risk of targeted phishing.

That distinction is crucial. Attackers do not necessarily need a private key or recovery phrase to steal cryptocurrency. Personal information can help them construct convincing messages that appear to know exactly which wallet, exchange or service a victim uses.

In the current campaign, that information can be combined with legitimate-looking email infrastructure to create a much more persuasive attack.

Security professionals have repeatedly emphasized that recovery phrases should never be entered into websites or provided to anyone claiming to offer technical support. Brevo’s own security guidance similarly warns that phishing messages commonly use urgency or threatening language to pressure recipients into acting before they verify the request independently.

The immediate lesson for users is straightforward: do not trust a security email simply because the sender address appears genuine.

Instead, users should open the official application or manually navigate to the company’s website rather than clicking an email link. Hardware-wallet recovery phrases should never be entered online, while exchange API credentials should be reviewed directly through the relevant account.

For Trezor, BitBox and CoinTracking users, the safest response to this latest phishing scam is to ignore the suspicious messages, avoid their links and verify any supposed security issue through official channels.

The broader investigation will determine whether the campaign was limited to the companies already identified or whether other cryptocurrency businesses using the same email infrastructure were affected. Until those answers emerge, crypto users should assume that a familiar brand name and a legitimate-looking sender are no longer enough to establish that an urgent security email is genuine.

Tags: . crypto newsBitBoxBlockchain SecurityCoinTrackingCrypto phishingcrypto Securitycryptocurrency scamscybersecurityemail breachPhishing campaignTrezorWallet Security
Share197Tweet123
Elizabeth Omotoke

Elizabeth Omotoke

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Phishing scam

Trezor, BitBox and CoinTracking warn of phishing campaign tied to shared email provider breach

09/11/2026
Russians Indicted For Crypto Laundering: U.S. Charges Trio for Operating Illicit Crypto Mixers

UK’s economic crime centre ranks crypto third-biggest threat, behind only lawyers and politically exposed persons

09/11/2026
Bitcoin ATM scams cost Americans $333 million in first 11 months of 2025, FBI reports

Albuquerque bans crypto ATMs citywide to fight scams targeting seniors

09/10/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.