{
  "id": 6549239,
  "title": "Trezor, BitBox warn users about fake hardware wallet security alerts",
  "url": "https://urgent.news/2026/09/10/trezor-bitbox-warn-users-about-fake-hardware-wallet-security-alerts",
  "topic": "finance",
  "section": "Finance & Markets",
  "published": "2026-09-10T05:34:21.000Z",
  "source": {
    "name": "Cointelegraph",
    "slug": "cointelegraph",
    "url": "https://cointelegraph.com/news/trezor-bitbox-hardware-wallet-phishing-emails"
  },
  "original_language": "en",
  "account": "Hardware wallet manufacturers Trezor and BitBox have issued warnings to users regarding a surge in phishing emails masquerading as urgent security alerts. The security breach at Trezor's email service was confirmed on Wednesday, with the company alerting users that a message titled \"Critical Security Alert: STM32 Entropy Vulnerability\" was deceptive. The email, allegedly part of a broader phishing campaign, urged recipients not to click any links. It is believed that multiple Bitcoin companies were targeted through a shared newsletter provider, according to BitBox's preliminary investigation, which indicated that various Bitcoin companies appeared to have been affected by a compromised newsletter provider. The warnings follow a series of recent security disclosures in the hardware-wallet sector, including Trezor's disclosure of a breach in its shipping provider ShipMonk that exposed data of almost 14,000 customers on August 13, and a disclosure of further data exposure to US customers on September 4. In July, BitBox stated that its devices were not impacted by a vulnerability related to Coldcard's random-number generation, and the following month, the company released an update addressing two severe firmware vulnerabilities, with no known exploitation or stolen funds reported. Cointelegraph attempted to reach Trezor and BitBox for more information but received no response prior to publication.",
  "summary": "BitBox said multiple Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor confirmed a breach at its email service.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}