← Backbitcoin

Trezor and BitBox Warn of Fake Security Alerts for Hardware Wallets

Team Coinnachrichten··📖 2 min read·TrezorBitBoxhardware walletssecurity warningsphishingrecovery phrasecryptonewsletter service providers
Trezor and BitBox Warn of Fake Security Alerts for Hardware Wallets📈 Bitcoin (BTC) View live price
If I've learned one thing about crypto in recent years, it's this: the hardware wallet is usually not the problem—the human in front of it is. That's exactly what criminals are once again increasingly exploiting. Trezor and BitBox (Shift Crypto) are sounding the alarm, and not without reason.
The trick is time-tested but apparently extremely dangerous: you receive an email that looks as if it came directly from Trezor or BitBox. Urgent tone, clear call to action. Supposedly there was a security incident, the firmware had been compromised, or the account had to be verified immediately. If you click on the link, you land on a deceptively real page that asks for the recovery phrase—the 12 or 24 words used to restore your coins. Anyone who enters them usually loses their money immediately.
What BitBox found out makes the matter unpleasant: apparently several Bitcoin companies were targeted through the same newsletter service provider. That means the wallets themselves were probably not hacked, but rather the providers' email channels. Trezor has now admitted that there was unauthorized access to its email service. Attackers may have gained access to real customer addresses—and are now sending out all the more convincing

Bybit Trade crypto on Bybit – low fees

Global, secure and regulated platform.

Open Bybit account →


phishing emails.
Both manufacturers say it crystal clear, and I can only repeat it: no reputable provider will ever ask for your recovery phrase by email, phone, or chat. Never. These words are the only key to your coins. Anyone who enters them digitally—no matter where—risks everything. If such a message arrives: delete it, don't click. If in doubt, open the official website directly in your browser and get information there.
For wallet owners, this is another wake-up call. The devices themselves are secure, the private keys never leave the hardware. But the human remains the weak point. Phishing does not target encryption, but carelessness. Anyone who keeps their recovery phrase offline—on paper or metal—and never types it into a browser, an app, or an email form is largely protected against this trick.
The industry is reacting: encrypted communication, warnings in the apps, two-factor authentication wherever possible. Nevertheless, the current case shows that phishing remains one of the biggest threats—as long as criminals can obtain large numbers of customer addresses with simple means. So: not only secure the wallet, but also the email account. And with unexpected security warnings, always be suspicious first.

📰 Read more

→ Bitcoin at $78,000: Macro Shocks Could Set the Direction→ Bitcoin ETFs Lose $167 Million After Record Inflows→ Bitcoin Selling Pressure Falls to Rare Lows


📢 Share this article

X Facebook WhatsApp Telegram Reddit

💬 Comments (0)

No comments yet.

📚 Weiterlesen

📖 Bitcoin halving explained🔍 bitcoin🔍 halving

📰 Related Articles

bitcoin

Bitcoin at $78,000: Macro Shocks Could Set the Direction

bitcoin

Bitcoin ETFs See Second Consecutive Day of Outflows – All Other Funds Gain

bitcoin

Singapore's SGX Opens Bitcoin and Ether Perpetuals to US Institutions

📱 QR-Code