Trezor, Bitbox, and Cointracking warned customers Thursday that phishing emails were sent through compromised mailing infrastructure, turning what looked like legitimate security notices into traps designed to steal information from cryptocurrency users.
Key Takeaways
- Trezor warned Sept. 10 that a breached email provider sent customers phishing messages.
- Cointracking said Brevo was breached as Bitbox reported multiple bitcoin firms targeted.
- Bitbox said most phishing links were down Sept. 9, but its investigation remains active.
The incident that occurred on Sept. 9 and 10 appears to stretch beyond a single company. Bitbox said multiple bitcoin companies were targeted and that the affected businesses appeared to share the same newsletter provider, while Cointracking identified its third-party email provider as Brevo.
Trezor Sounds the Alarm Over a Fake Security Warning
Trezor told customers that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” did not come from the hardware wallet manufacturer and warned recipients not to click any links. The company said its third-party email provider had been breached.
The attack had an especially nasty twist: Trezor said hackers gained access to its legitimate domain. That can make phishing considerably harder to spot because users accustomed to checking the sender may see familiar infrastructure and assume the message is safe. Trezor said the malicious domain had been taken down and an investigation was underway.
Bitbox Finds Signs of a Wider Attack
On the flip side, this was not simply a Trezor problem. Bitbox said its preliminary investigation indicated its newsletter provider was likely compromised after a phishing message reached subscribers. More importantly, the company said several other bitcoin businesses were targeted and appeared to use the same provider.
Bitbox X post on Sept. 9, 2026, sending out a security warning.Bitbox responded by sending its own phishing warning, contacting the provider, and reporting malicious domains. Most of the phishing links had already been taken down when the company issued its statement, although its investigation remained active.
Cointracking Names Brevo as Its Compromised Provider
Cointracking, a cryptocurrency portfolio tracker and tax platform, provided another piece of the puzzle by identifying Brevo as the third-party email service provider involved in its incident.
Its customers received a bogus message titled “Data Breach Notice: Please refresh API Keys as soon as possible.” Cointracking stressed that the message was phishing, told customers not to click its links, and said it was investigating the breach.
“Do not click on any links contained in this email. We are currently investigating the incident and will provide further information as soon as it becomes available,” Cointracking wrote.
Crypto Firms Face Another Round of Customer Security Threats
The timing is a tough pill to swallow for hardware wallet users. Safepal and Trezor separately suffered customer-data leaks in August, although neither incident compromised seed phrases, private keys, or wallet funds.
SafePal said an authorization flaw exposed information belonging to about 39,798 customers, while Trezor’s Shipmonk-related leak ultimately affected roughly 81,000 orders. Names, addresses, phone numbers, and other customer information can give attackers material for more convincing phishing attempts even when the wallets themselves remain secure.
The Security Race Is Picking Up Steam
The broader threat is also changing as artificial intelligence makes finding software vulnerabilities cheaper and faster. In May, Taylor Hornby used Claude Opus 4.8 to uncover a four-year-old Zcash Orchard flaw, while Anthropic agents later reproduced hundreds of historical decentralized finance (DeFi) exploits representing about $550 million in simulated losses.
In August, a volunteer Bitcoin Red Team scanned 390 projects and filed 4,962 findings in roughly 30 hours, including 85 classified as critical. Researchers and attackers increasingly have access to the same powerful tools, leaving crypto companies walking a tightrope where the decisive question may simply be who finds the weakness first.
For Trezor, Bitbox, and Cointracking customers, the immediate priority is simpler: avoid the identified phishing emails and their links while the companies investigate what happened. What comes next depends on how the shared email infrastructure was compromised, how broadly the attack spread, and whether additional cryptocurrency companies disclose similar incidents.

1 hour ago
21









English (US) ·