Trezor users targeted in phishing wave after Brevo breach
Hackers sent 347,000 malicious emails to hardware wallet users by exploiting a flaw in a third-party marketing platform.
Trezor has confirmed that a security breach at its third-party email marketing provider has exposed hundreds of thousands of its customers to a sophisticated phishing campaign. The incident highlights a growing trend of supply chain vulnerabilities targeting the cryptocurrency ecosystem.
According to reports from TechCrunch and BleepingComputer, the breached provider, marketing tech company Brevo, suffered a flaw where access was wrongly granted to all reachable organizations. This vulnerability allowed hackers to access 138 Brevo accounts, which they then used to send approximately 347,000 phishing emails to Trezor customers. These messages utilized alarming subject lines—including one titled “Critical Security Alert: STM32 Entropy Vulnerability”—to trick users into downloading a malicious application designed to steal wallet backup passwords.
A Pattern of Third-Party Failures
This event marks the second major third-party security failure affecting Trezor in just two months. In August, a breach at shipping partner ShipMonk exposed the personal data of approximately 81,000 customers, including names, phone numbers, and physical addresses. That previous leak led to physical mail phishing attempts and increased the risk of "wrench attacks," where attackers use personal information to coerce users into revealing their keys.
The Supply Chain Risk
While Trezor stated that its own products, wallets, and internal account systems were not affected by the Brevo incident, the breach underscores a systemic risk in the industry. The security of a hardware wallet is designed to be absolute at the device level, yet that protection is frequently undermined by the vulnerabilities of the vendors used for logistics and marketing. Because stolen backup passwords allow hackers to irreversibly drain funds directly from the blockchain, these "side-door" attacks are often more effective than attempting to crack the hardware itself.
What to Watch
Users are urged to ignore any emails requesting the download of software or the entry of backup phrases. Trezor has explicitly warned that the "Critical Security Alert" email is a phishing attempt and did not originate from the company. Industry analysts will likely monitor whether other companies using Brevo's services were similarly targeted, as the breach involved a broad scoping flaw across multiple organizations.