Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Hackers Compromise Email Providers to Launch Phishing Campaign Against Crypto Users

Trezor, Bitbox, and Cointracking warned customers of phishing emails sent through compromised mailing infrastructure on September 9 and 10, with evidence suggesting multiple cryptocurrency firms were targeted through a shared email provider.
4 hours ago 7 views
Hackers Compromise Email Providers to Launch Phishing Campaign Against Crypto Users

Cryptocurrency hardware wallet and portfolio tracking services Trezor, Bitbox, and Cointracking alerted customers Thursday to phishing emails sent through compromised email infrastructure. The attacks, which occurred September 9 and 10, appear to have affected multiple cryptocurrency businesses that shared third-party email providers.

Trezor's Compromised Domain

Trezor warned customers that a phishing email titled "Critical Security Alert: STM32 Entropy Vulnerability" did not originate from the company. The message was sent after hackers gained access to Trezor's legitimate email domain, making the phishing attempt difficult to detect for users checking sender information. Trezor advised customers not to click any links in the email and said the malicious domain had been taken down with an investigation underway.

Broader Attack Pattern Emerges

Bitbox's investigation indicated its newsletter provider was likely compromised, resulting in a phishing message reaching subscribers. The company reported that several other bitcoin businesses appeared to have been targeted and used the same email provider. Most phishing links were already offline when Bitbox issued its security warning, though the company's investigation continued.

Cointracking, a cryptocurrency portfolio tracker and tax platform, identified its compromised email provider as Brevo. Customers received a bogus message titled "Data Breach Notice: Please refresh API Keys as soon as possible." Cointracking warned users not to click links in the email and stated it was investigating the incident.

Context of Recent Security Incidents

The phishing campaign adds to recent security challenges for cryptocurrency users. SafePal and Trezor separately experienced customer data leaks in August. SafePal reported an authorization flaw that exposed information for approximately 39,798 customers, while Trezor's incident related to its shipping partner Shipmonk affected roughly 81,000 orders. Neither incident compromised seed phrases, private keys, or wallet funds. However, the exposed customer information—including names, addresses, and phone numbers—can provide attackers material for more convincing phishing attempts.

Evolving Security Landscape

The cryptocurrency industry faces expanding security threats as technological tools evolve. In August, a volunteer Bitcoin Red Team scanned 390 projects and filed 4,962 findings in approximately 30 hours, including 85 classified as critical.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $77,307.75-1.68% EthereumETH $2,441.16-2.01% Tether USDUSDT $1.00-0.01% BNBBNB $708.91-4.37% XRPXRP $1.36-4.26% USDCUSDC $1.000.00% SolanaSOL $99.97-2.94% TRONTRX $0.3387+0.01% HyperliquidHYPE $81.03-5.38% ZcashZEC $1,174.33-7.67%
Prices by Coinranking. Informational only.