This Week in Crypto: Trezor Phishing Attack Raises Cold Storage Questions
This week in crypto, security returned to the spotlight after Trezor and BitBox users were targeted by unusually convincing phishing campaigns linked to compromised third-party email infrastructure. The incidents add to a difficult period for hardware wallets following the recent Coldcard attacks and other security concerns, raising broader questions about the risks and responsibilities that come with self-custody. Elsewhere, MoneyGram expanded its stablecoin payment push, US lawmakers faced renewed pressure to progress the CLARITY Act, and activity on Solana reached a new milestone.
Trezor confirmed that a third-party email provider had been compromised and used to distribute fraudulent security warnings to customers. Unlike typical phishing attempts, the emails were sent through infrastructure authorised to communicate on Trezor's behalf, allowing them to appear legitimate and making them more difficult for users and email filters to identify as malicious. Recipients were warned of a supposed vulnerability affecting their wallet and encouraged to complete a security verification process designed to capture sensitive information.
Trezor was not alone. BitBox users received similar phishing emails at around the same time, with the company saying its preliminary investigation suggested its newsletter provider had also been compromised. BitBox said multiple Bitcoin companies appeared to have been targeted through a shared provider, pointing to a broader campaign against users of crypto security products rather than an isolated attack on one company.
Importantly, there is currently no indication that Trezor or BitBox hardware wallets themselves were compromised in the phishing campaign. Instead, attackers targeted the infrastructure and people surrounding them, demonstrating how criminals can bypass the security of the physical device altogether. The timing is particularly notable following the Coldcard vulnerability earlier this year, while BitBox disclosed and patched two serious firmware vulnerabilities in August.
Trezor has also been dealing with the fallout from a separate breach involving shipping provider ShipMonk. The company initially reported that data belonging to almost 14,000 customers had been exposed, before revealing in September that a further 67,000 US customers were affected. Information exposed included names, contact details and, for some customers, shipping and order information, potentially increasing the risk of targeted phishing and social engineering attacks.
Together, these incidents are sparking a broader conversation around what secure crypto custody actually looks like. Hardware wallets can provide strong protection by keeping private keys away from online platforms, but self-custody also transfers significantly more responsibility to the individual. Recovery phrases, firmware, physical backups and increasingly sophisticated phishing attempts all become risks users must understand and manage themselves. For experienced users, that level of control can be an advantage. For everyday crypto holders, recent events are a reminder that cold storage is not automatically the safest option simply because assets are held offline.
Away from security, stablecoins took another step towards everyday use this week as MoneyGram announced a stablecoin-backed Visa card in Colombia. The virtual card will allow eligible customers to hold stablecoin balances and spend through Visa's existing payment network, with a physical version and expansion into additional markets planned. The launch builds on MoneyGram's growing blockchain strategy, including its MGUSD stablecoin and integrations connecting digital assets with its global remittance network.
The move reflects a broader shift in how stablecoins are being used. Rather than serving primarily as a way to move funds between crypto platforms, they are increasingly being connected with familiar financial products such as cards, wallets and international transfers. MoneyGram's expansion, alongside similar initiatives from other payment providers, suggests stablecoins are becoming an increasingly important part of the competition to modernise cross-border payments.
Regulation also returned to focus in the United States, with Treasury Secretary Scott Bessent urging senators to continue negotiations on the CLARITY Act when lawmakers return from their August recess. The legislation aims to establish a comprehensive framework for digital asset markets and provide clearer boundaries for how cryptocurrencies and trading platforms are regulated.
Time, however, is becoming a major obstacle. The Senate has a narrow legislative window remaining this year, while disagreements around areas including stablecoin rewards and political ethics provisions remain unresolved. Galaxy Digital has reduced its estimated probability of the legislation passing in 2026 to just 10%, down substantially from earlier in the year. Failure to reach an agreement could push US crypto market structure reform into the next Congress, where the legislation could face a very different political environment.
Finally, activity on Solana reached a new record, with more than 263,000 SPL tokens created in a single day. That was substantially higher than daily issuance during the peak of the memecoin cycle in late 2024, when tens of thousands of new tokens were typically being launched each day.
Launch platforms have made creating and trading new tokens increasingly accessible, with Pump.fun responsible for much of the recent activity. The record highlights the scale Solana's token ecosystem has reached, but also the changing nature of blockchain participation as launching a new digital asset becomes easier than ever.
This week's developments show two very different sides of crypto's continued growth. Stablecoins and blockchain payment infrastructure are moving deeper into mainstream finance, while networks such as Solana continue to lower the barriers to creating digital assets. At the same time, increasingly sophisticated attacks are testing how users protect those assets. As crypto becomes easier to access and use, making security equally accessible may prove just as important to the industry's next stage of adoption.
Other news: