Hardware wallet manufacturers Trezor and BitBox have alerted their customers to a wave of phishing emails impersonating official security notifications, warning that scammers are attempting to trick users into surrendering access to their crypto holdings.
What Happened
Both companies issued public warnings after fraudulent messages designed to look like legitimate security alerts began circulating among their user bases. The emails mimic official communications, a common tactic aimed at pressuring recipients into acting quickly before they can spot the deception.
BitBox indicated that several Bitcoin-focused companies appeared to have been hit through a common weak point: a shared newsletter provider. When a third-party service that handles email distribution is compromised, attackers can potentially reach the customers of multiple firms at once.
Trezor, meanwhile, confirmed that its email service provider had suffered a breach, opening the door for malicious actors to send messages that appeared to come from the company itself.
Never enter your recovery seed anywhere but directly on your hardware wallet device.
How the Scams Work
Phishing campaigns targeting crypto holders typically try to lure victims into revealing their recovery seed phrase or private keys. Once an attacker obtains that information, they can drain a wallet's contents with no way for the victim to recover the funds.
Hardware wallets are designed to keep private keys offline and away from internet-connected devices, making them a popular choice for securing digital assets. That same reputation, however, makes their users attractive targets for social engineering attacks that attempt to bypass the device entirely by manipulating the person behind it.
Users should keep the following precautions in mind:
- Legitimate wallet firms will never ask for a recovery seed via email
- Treat urgent security warnings with skepticism and verify them independently
- Recovery phrases should only ever be entered on the hardware device itself
The incidents underscore a persistent risk in the crypto industry, where third-party service providers can become the entry point for attacks even when a company's core products remain secure.
