Attackers used compromised email providers to send fake security alerts to Trezor and BitBox users, aiming to steal wallet recovery seeds. The incident underscores ongoing risks for hardware wallet holders and the need for careful security practices.
Users of hardware wallets have been hit by another phishing campaign, this time after attackers gained access to third-party email and newsletter services used by Trezor and BitBox. The fake emails, which looked like urgent security warnings, tried to trick people into revealing their wallet recovery seeds-giving criminals a way to empty their accounts.
Fake security alerts
The phishing campaign exploited trusted email channels, making fraudulent messages appear authentic and increasing the risk of users divulging their recovery seeds.
Third-party provider breach
According to Trezor and BitBox, attackers used legitimate email distribution systems to send phishing messages that looked real. Trezor said it had already taken down the malicious domain used in the attack and was investigating how the breach happened. BitBox found that other Bitcoin-related companies using the same newsletter provider may have been targeted as well. Most phishing links were disabled soon after the warnings went out, but investigations are still ongoing.
User risks and security guidance
While Trezor and BitBox reassured users that their wallets were not directly compromised, the real risk comes from social engineering. If someone enters their recovery seed-a backup phrase that controls wallet access-on a phishing site, attackers can immediately steal all assets from the wallet. Both companies repeated their usual advice: never share your recovery seed, avoid suspicious links, and check any security messages through official channels. Only download wallet software from the official website, and treat any unexpected security alert with caution.
Broader security context
Hardware wallets like Trezor and BitBox are designed to keep private keys offline, but phishing attacks can bypass device security by targeting users directly. The irreversible nature of blockchain transactions means that once a seed phrase is compromised, stolen funds are almost never recoverable.
Hardware wallet makers do not publish numbers on how many users are affected by phishing, but the risk is high because crypto transactions cannot be reversed. Chainalysis reports that phishing and social engineering scams led to over $1 billion in crypto losses worldwide in 2025, with hardware wallet users increasingly targeted as attackers shift from direct hacks to exploiting human mistakes.
Phishing in the crypto world often relies on urgency, technical language, and impersonating trusted brands to pressure users into giving up sensitive information. Unlike traditional bank fraud, stolen crypto is rarely recovered because of how blockchain works. This makes personal security habits-like never sharing a recovery seed and always verifying communications-essential for anyone using self-custody wallets.