READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Trezor's Email Vendor Got Hacked, So Scammers Blasted 347,000 Crypto Owners With Fake Security Alerts

Trezor's Email Vendor Got Hacked, So Scammers Blasted 347,000 Crypto Owners With Fake Security Alerts
Hackers broke into Trezor's email marketing vendor Brevo and used it to blast 347,000 phishing emails from Trezor's own domain, tricking recipients into a fake microcontroller vulnerability scare. It's the second Trezor vendor breach in as many months, following an August hack of its shipping partner that exposed over 81,000 customers' addresses. This is what happens when a hardware wallet maker outsources its customer communications and never audits who's holding the keys.

Trezor customers got an email this week that looked exactly like it came from the company: right domain, right branding, subject line built to trigger panic. It read: "Critical Security Alert: STM32 Entropy Vulnerability." The email was a scam, sent because the company's own systems got hijacked by someone else's mistake. Trezor confirmed in a blog post this week that Brevo, the marketing platform it uses to send newsletters, was breached. Attackers used that access to send roughly 347,000 phishing emails to Trezor customers, according to TechCrunch. The emails came from Trezor's legitimate sending domain, which is exactly why they worked. The phishing email, detailed by Malwarebytes, claimed Trezor's engineering team had found "a critical hardware-level vulnerability in the STM32 microcontrollers," supposedly affecting one in four devices initialized before 2023. None of that is true. The email pushed recipients to download an app and enter their wallet backup password. Anyone who did that handed a stranger the keys to their crypto. Trezor said funds stolen this way are gone for good, since blockchain transactions can't be reversed.

How Brevo got hit

Brevo, the email platform, said in an incident status update that attackers exploited a flaw in how the company handles SAML single sign-on, gaining access to 138 customer accounts, according to Malwarebytes. Six of those accounts were used to actually send phishing emails. Attackers exported contact lists from 43 more. The remaining 93 accounts showed no meaningful activity. Brevo said the access was "wrongly granted" to organizations the attackers' accounts shouldn't have been able to reach, a scoping failure on Brevo's end, not Trezor's. Trezor wasn't the only victim. CoinTracking and BitBox, two other cryptocurrency companies that use Brevo, also had phishing emails sent to their customers, according to Malwarebytes. CoinTracking's version told recipients to "refresh API keys." Trezor says it moved fast once the campaign was spotted. Trezor also suspended its Brevo account to stop further emails. The company has been blunt: no other Trezor system, wallet, or account infrastructure was touched. This was entirely a vendor-side failure.

The second breach in two months

This is Trezor's second vendor breach since August. Its shipping partner, ShipMonk, was compromised, exposing names, phone numbers, emails, and postal addresses. Bitcoin Magazine reported the number climbed from an initial 11,742 affected customers to an additional 67,000 U.S. customers, putting the total above 81,000 people whose physical addresses are now in criminal hands. Crypto owners with known holdings and known home addresses are targets for so-called "wrench attacks," physical assaults meant to force victims to hand over wallet passwords. TechCrunch reported that in the weeks following the ShipMonk breach, some customers received fake letters in the mail with QR codes designed to steal wallet backup passwords when scanned. Crypto hardware makers have had a rough stretch generally. Bitcoin Magazine noted that Ledger customers were targeted after its payment processor Global-e was compromised, and wallet provider SafePal disclosed a breach exposing nearly 40,000 customers' order information last month.

The fair criticism, and the limits of it Security researchers have a legitimate point here

hardware wallet companies built their entire pitch on being the secure, offline alternative to exchanges, yet they keep outsourcing core customer-facing functions, like email and shipping, to third-party vendors with their own security failures. That's a real structural weakness, not a hypothetical one. Two breaches in two months at one company is a pattern. Trezor isn't denying that. The company said it's reevaluating its vendor relationships and has warned customers their email addresses could be reused in future phishing attempts. That's a straightforward acknowledgment that the vetting process for Brevo and ShipMonk wasn't good enough the first time. Trezor hasn't released a dollar figure or a victim count for actual theft, only the click-through number before the domain was taken down. Whether this campaign resulted in significant losses, or was mostly caught before real damage was done, remains an open question the company hasn't answered.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchScammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
unknown
Shattered.ioTrezor Email Breach: 347K Phishing Emails Sent [2026]
unknown
primanewsScammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
unknown
Bitcoin MagazineTrezor Reveals Another Data Breach
unknown
Europe SaysScammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
unknown
MalwarebytesCrypto customers targeted by scammers after email marketing provider breach
unknown
itsecuritynews.infoTrezor Says 347,000 Users Received Phishing Emails After Brevo Hack - IT Security News