Cryptocurrency hardware wallet and portfolio tracking services Trezor, Bitbox, and Cointracking alerted customers Thursday to phishing emails sent through compromised email infrastructure. The attacks, which occurred September 9 and 10, appear to have affected multiple cryptocurrency businesses that shared third-party email providers.
Trezor's Compromised Domain
Trezor warned customers that a phishing email titled "Critical Security Alert: STM32 Entropy Vulnerability" did not originate from the company. The message was sent after hackers gained access to Trezor's legitimate email domain, making the phishing attempt difficult to detect for users checking sender information. Trezor advised customers not to click any links in the email and said the malicious domain had been taken down with an investigation underway.
Broader Attack Pattern Emerges
Bitbox's investigation indicated its newsletter provider was likely compromised, resulting in a phishing message reaching subscribers. The company reported that several other bitcoin businesses appeared to have been targeted and used the same email provider. Most phishing links were already offline when Bitbox issued its security warning, though the company's investigation continued.
Cointracking, a cryptocurrency portfolio tracker and tax platform, identified its compromised email provider as Brevo. Customers received a bogus message titled "Data Breach Notice: Please refresh API Keys as soon as possible." Cointracking warned users not to click links in the email and stated it was investigating the incident.
Context of Recent Security Incidents
The phishing campaign adds to recent security challenges for cryptocurrency users. SafePal and Trezor separately experienced customer data leaks in August. SafePal reported an authorization flaw that exposed information for approximately 39,798 customers, while Trezor's incident related to its shipping partner Shipmonk affected roughly 81,000 orders. Neither incident compromised seed phrases, private keys, or wallet funds. However, the exposed customer information—including names, addresses, and phone numbers—can provide attackers material for more convincing phishing attempts.
Evolving Security Landscape
The cryptocurrency industry faces expanding security threats as technological tools evolve. In August, a volunteer Bitcoin Red Team scanned 390 projects and filed 4,962 findings in approximately 30 hours, including 85 classified as critical.


