
Hardware wallet maker Trezor is warning customers that a breach at one of its email providers exposed user data to attackers, enabling a large phishing campaign aimed at crypto owners. The company said the incident involved Brevo, a marketing platform Trezor uses to send newsletters, and that hackers were able to send around 347,000 malicious emails impersonating Trezor.
Trezor says attackers sent hundreds of thousands of fake alerts
According to Trezor, the phishing messages used a subject line that included “Critical Security Alert: STM32 Entropy Vulnerability,” designed to look urgent and technical enough to push recipients into clicking quickly. The link in the email reportedly led to an app that asked victims for their wallet backup password.
That detail matters because anyone who reveals a wallet backup password, sometimes called a recovery phrase or seed-related credential in broader consumer language, could lose access to their crypto holdings permanently. On public blockchains, transfers are usually irreversible once an attacker gains control of a wallet.
What Brevo says happened
Brevo said in an incident status update that hackers accessed 138 Brevo accounts and used them to distribute the phishing campaign. The company said the attackers exploited a flaw that meant their access was “not properly scoped,” and that it was “wrongly granted” to all organizations the compromised accounts could reach.
In practical terms, that created a path for the attackers to send messages at scale using legitimate-looking infrastructure rather than obvious spam systems. That tends to make phishing emails harder for both users and email filters to spot.
Why third-party breaches keep hitting crypto brands
The incident underscores a familiar weakness in the supply chain around consumer-facing security and financial products: even if the core platform is not breached, data held by service providers can still be abused. Companies that handle newsletters, shipping, customer support, or other operational functions often possess customer contact details that are valuable to attackers.
Trezor said none of its products, wallets, or account systems were affected by the Brevo incident. But the company also warned that customers’ email addresses may be reused in future phishing attempts, suggesting attackers may still have access to usable contact information.
A second breach for Trezor in recent weeks
This is the second security-related disclosure Trezor has made in as many months. In August, the company said a compromise at shipping partner ShipMonk exposed customer data tied to at least 81,000 people who bought and received Trezor hardware wallets.
That breach exposed names, phone numbers, email addresses and postal addresses. It also raised concerns beyond email scams, because knowledge of a person’s crypto holdings can increase the risk of targeted theft or physical coercion.
Growing concern over “wrench” attacks
The term “wrench attack” refers to physical violence or intimidation used to force someone to reveal passwords, seed phrases or wallet access. The risk is especially sensitive for crypto owners with high balances, public profiles or visible signs of wealth.
After the ShipMonk incident, Trezor said some people received letters in the mail claiming to be from the company. Those letters reportedly included a QR code that opened a fake page designed to steal wallet backup information, showing how stolen customer data can be turned into multi-channel fraud.
How the phishing campaign likely worked
The latest attack appears to have followed a classic pattern: use a compromised but trusted sending service, craft a message that sounds like a security warning, and direct recipients to a fake page or app that requests sensitive credentials. Because the messages came through legitimate email infrastructure, they may have appeared more credible than typical spam.
Trezor’s warning suggests the attackers were trying to exploit fear and urgency. Security-themed subject lines are especially effective when they reference a technical issue that most recipients will not understand at a glance.
- Brevo said 138 accounts were used in the campaign.
- Trezor said around 347,000 phishing emails were sent.
- The subject line cited by Trezor was “Critical Security Alert: STM32 Entropy Vulnerability.”
- Trezor said its products, wallets and account system were not affected.
What Trezor customers should watch for
Trezor has already warned users that their email addresses could be reused in future attacks, so recipients should assume future scams may be highly tailored and visually convincing. The safest response is to ignore unsolicited requests to enter wallet backup details, even if they appear to come from a familiar brand.
Users should also be cautious about QR codes, shortened links, urgent “security alert” emails and any message that pressures them to install software or enter recovery information immediately. When in doubt, the safest move is to access the company through a known bookmark or manually typed address rather than through links in email.
Why the fallout may continue
Phishing campaigns often continue after the initial incident because the underlying contact data remains useful to criminals. Even when companies reset access or patch the service involved, the stolen email lists can be repurposed for follow-on scams, fake support messages and social-engineering attempts.
For crypto users, that means the danger is not limited to the day the breach is disclosed. The same stolen data can support fraud attempts for weeks or months, especially when attackers know the target is likely to own digital assets.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 11, 2026 at 10:32 pm
8 views

