{"id":77971,"date":"2026-09-10T10:47:31","date_gmt":"2026-09-10T10:47:31","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/hackers-hijack-trezor-bitbox-emails-to-target-crypto-users\/"},"modified":"2026-09-10T10:47:31","modified_gmt":"2026-09-10T10:47:31","slug":"hackers-hijack-trezor-bitbox-emails-to-target-crypto-users","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/hackers-hijack-trezor-bitbox-emails-to-target-crypto-users\/","title":{"rendered":"Hackers Hijack Trezor, Bitbox Emails to Target Crypto Users"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Trezor warned Sept. 10 that a breached email provider sent customers phishing messages.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Cointracking said Brevo was breached as Bitbox reported multiple bitcoin firms targeted.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Bitbox said most phishing links were down Sept. 9, but its investigation remains active.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p>The incident that occurred on Sept. 9 and 10 appears to stretch beyond a single company. <a href=\"https:\/\/x.com\/BitBoxSwiss\/status\/2097793026336981079?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">Bitbox said multiple bitcoin companies were targeted<\/a> and that the affected businesses appeared to share the same newsletter provider, while Cointracking identified its third-party email provider as Brevo.<\/p>\n<h2>Trezor Sounds the Alarm Over a Fake Security Warning<\/h2>\n<p><a href=\"https:\/\/x.com\/Trezor\/status\/2097786518110609620?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">Trezor told customers<\/a> that an email titled \u201cCritical Security Alert: STM32 Entropy Vulnerability\u201d did not come from the hardware wallet manufacturer and warned recipients not to click any links. The company said its third-party email provider had been breached.<\/p>\n<p>The attack had an especially nasty twist: Trezor said hackers gained access to its legitimate domain. That can make phishing considerably harder to spot because users accustomed to checking the sender may see familiar infrastructure and assume the message is safe. Trezor said the malicious domain had been taken down and an investigation was underway.<\/p>\n<h2>Bitbox Finds Signs of a Wider Attack<\/h2>\n<p>On the flip side, this was not simply a Trezor problem. Bitbox said its preliminary investigation indicated its newsletter provider was likely compromised after a phishing message reached subscribers. More importantly, the company said several other bitcoin businesses were targeted and appeared to use the same provider.<\/p>\n<figure id=\"attachment_846370\" aria-describedby=\"caption-attachment-846370\" style=\"width:1320px\" class=\"wp-caption aligncenter\"><figcaption id=\"caption-attachment-846370\" class=\"wp-caption-text\">Bitbox X post on Sept. 9, 2026, sending out a security warning.<\/figcaption><\/figure>\n<p>Bitbox responded by sending its own phishing warning, contacting the provider, and reporting malicious domains. Most of the phishing links had already been taken down when the company issued its statement, although its investigation remained active.<\/p>\n<h2>Cointracking Names Brevo as Its Compromised Provider<\/h2>\n<p>Cointracking, a cryptocurrency portfolio tracker and tax platform, <a href=\"https:\/\/x.com\/Coin_Tracking\/status\/2097800407103783325\" target=\"_blank\" rel=\"noopener noreferrer\">provided another piece of the puzzle<\/a> by identifying Brevo as the third-party email service provider involved in its incident.<\/p>\n<p>Its customers received a bogus message titled \u201cData Breach Notice: Please refresh API Keys as soon as possible.\u201d Cointracking stressed that the message was phishing, told customers not to click its links, and said it was investigating the breach.<\/p>\n<p>\u201cDo not click on any links contained in this email. We are currently investigating the incident and will provide further information as soon as it becomes available,\u201d Cointracking wrote.<\/p>\n<h2>Crypto Firms Face Another Round of Customer Security Threats<\/h2>\n<p>The timing is a tough pill to swallow for hardware wallet users. Safepal and Trezor separately <a href=\"https:\/\/news.bitcoin.com\/security\/data-breach-hits-39798-safepal-customers-after-order-plugin-flaw\/\">suffered customer-data leaks<\/a> in August, although neither incident compromised seed phrases, private keys, or wallet funds.<\/p>\n<p>SafePal said an authorization flaw exposed information belonging to about 39,798 customers, while <a href=\"https:\/\/news.bitcoin.com\/security\/trezor-data-leak-spirals-as-67000-more-us-buyers-get-exposed\/\">Trezor\u2019s Shipmonk-related leak<\/a> ultimately affected roughly 81,000 orders. Names, addresses, phone numbers, and other customer information can give attackers material for more convincing phishing attempts even when the wallets themselves remain secure.<\/p>\n<h2>The Security Race Is Picking Up Steam<\/h2>\n<p>The broader threat is also changing as artificial intelligence makes finding software vulnerabilities cheaper and faster. In May, Taylor Hornby used Claude Opus 4.8 to uncover a <a href=\"https:\/\/news.bitcoin.com\/crypto-news\/ironwood-goes-live-as-zcash-locks-down-orchard-and-forces-a-1-8b-migration\/\">four-year-old Zcash Orchard flaw<\/a>, while Anthropic agents later reproduced hundreds of historical decentralized finance (DeFi) exploits representing about $550 million in simulated losses.<\/p>\n<p>In August, a volunteer Bitcoin Red Team scanned 390 projects and <a href=\"https:\/\/news.bitcoin.com\/security\/bitcoin-red-team-audit-coldcard-vulnerabilities\/\">filed 4,962 findings in roughly 30 hours<\/a>, including 85 classified as critical. Researchers and attackers increasingly have access to the same powerful tools, leaving crypto companies walking a tightrope where the decisive question may simply be who finds the weakness first.<\/p>\n<p>For Trezor, Bitbox, and Cointracking customers, the immediate priority is simpler: avoid the identified phishing emails and their links while the companies investigate what happened. What comes next depends on how the shared email infrastructure was compromised, how broadly the attack spread, and whether additional cryptocurrency companies disclose similar incidents.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/security\/hackers-hijack-trezor-bitbox-emails-to-target-crypto-users\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Trezor warned Sept. 10 that a breached email provider sent customers phishing messages. Cointracking said Brevo was breached as Bitbox reported multiple bitcoin firms targeted. Bitbox said most phishing links were down Sept. 9, but its investigation remains active. The incident that occurred on Sept. 9 [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":77972,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/77971"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=77971"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/77971\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/77972"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=77971"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=77971"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=77971"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}