TechNewsReel
Live

Crypto Hardware Wallet Users Targeted in Brevo Email Breach Phishing Campaign

Attackers leveraged compromised accounts at email provider Brevo to send authenticated phishing lures to Trezor and BitBox subscribers.

TechNewsReel Newsroom · September 10, 2026

Subscribers of leading cryptocurrency hardware wallet firms were targeted in a sophisticated phishing campaign after attackers compromised a third-party email service provider. The breach allowed malicious actors to send highly convincing security alerts directly through legitimate mailing channels, bypassing traditional email filters.

The attack originated at Brevo, formerly known as Sendinblue, where attackers gained access to approximately 120 accounts. Using these compromised accounts, the attackers sent phishing emails to the contact bases of several crypto-focused firms, including Trezor, BitBox, and CoinTracking.

Trezor users were sent emails titled "Critical Security Alert: STM32 Entropy Vulnerability," which falsely claimed that a hardware defect affected one in four devices and demanded that users provide their wallet backups. Similarly, BitBox users received emails titled "Critical Security Alert: Microcontroller Entropy Bug Identified," which warned of entropy weaknesses in their devices. In response, Trezor urged users to ignore the messages, stating, "Do not click it or interact with it. Never enter your wallet backup anywhere. Always confirm every action with your Trezor physically."

The Danger of Authenticated Phishing

This campaign is particularly dangerous because the emails were dispatched via legitimate provider accounts. By using Brevo's own infrastructure, the phishing messages were able to bypass standard email authentication checks, such as SPF, DKIM, and DMARC. These protocols are designed to prevent spoofing by verifying the sender's identity; however, because the accounts themselves were compromised, the emails appeared authentic to both mail servers and users.

By targeting the "root of trust"—the seed phrases and wallet backups—the attackers aimed for total control over user funds. In the context of hardware wallets, once a backup phrase is revealed to a third party, the security provided by the physical device is completely negated, leading to an immediate and total loss of assets.

A Pattern of Third-Party Vulnerabilities

This incident follows a separate, significant security failure involving Trezor's supply chain. The company's logistics partner, ShipMonk, suffered a data breach that exposed the personal details of approximately 80,000 customers. This exposure occurred in stages, initially affecting around 13,000 users and later expanding to include an additional 67,000 U.S. customers between 2019 and 2021.

The repeated compromise of third-party vendors highlights a growing vulnerability in the crypto industry: the "side-channel" attack. While the hardware wallets themselves may remain secure, the ecosystem of logistics and marketing partners creates a wider attack surface that hackers can exploit to gather intelligence or launch targeted social engineering campaigns.

What to Watch

Users are advised to remain vigilant against any email requesting sensitive keys or backups, regardless of whether the sender appears legitimate. Security experts continue to monitor for further account compromises within Brevo and similar service providers. It remains to be seen if other crypto-related firms using the same provider were targeted in this wave of authenticated phishing.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.