Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Trezor's Email Vendor Got Hacked, So Scammers Blasted 347,000 Crypto Owners With Fake Security Alerts

Trezor customers got an email this week that looked exactly like it came from the company: right domain, right branding, subject line built to trigger panic. It read: "Critical Security Alert: STM32 Entropy Vulnerability." The email was a scam, sent because the company's own systems got hijacked by someone else's mistake. Trezor confirmed in a blog post this week that Brevo, the marketing platform it uses to send newsletters, was breached. Attackers used that access to send roughly 347,000 phishing emails to Trezor customers, according to TechCrunch. The emails came from Trezor's legitimate sending domain, which is exactly why they worked. The phishing email, detailed by Malwarebytes, claimed Trezor's engineering team had found "a critical hardware-level vulnerability in the STM32 microcontrollers," supposedly affecting one in four devices initialized before 2023. None of that is true. The email pushed recipients to download an app and enter their wallet backup password. Anyone who did that handed a stranger the keys to their crypto. Trezor said funds stolen this way are gone for good, since blockchain transactions can't be reversed.
How Brevo got hit
Brevo, the email platform, said in an incident status update that attackers exploited a flaw in how the company handles SAML single sign-on, gaining access to 138 customer accounts, according to Malwarebytes. Six of those accounts were used to actually send phishing emails. Attackers exported contact lists from 43 more. The remaining 93 accounts showed no meaningful activity. Brevo said the access was "wrongly granted" to organizations the attackers' accounts shouldn't have been able to reach, a scoping failure on Brevo's end, not Trezor's. Trezor wasn't the only victim. CoinTracking and BitBox, two other cryptocurrency companies that use Brevo, also had phishing emails sent to their customers, according to Malwarebytes. CoinTracking's version told recipients to "refresh API keys." Trezor says it moved fast once the campaign was spotted. Trezor also suspended its Brevo account to stop further emails. The company has been blunt: no other Trezor system, wallet, or account infrastructure was touched. This was entirely a vendor-side failure.
The second breach in two months
This is Trezor's second vendor breach since August. Its shipping partner, ShipMonk, was compromised, exposing names, phone numbers, emails, and postal addresses. Bitcoin Magazine reported the number climbed from an initial 11,742 affected customers to an additional 67,000 U.S. customers, putting the total above 81,000 people whose physical addresses are now in criminal hands. Crypto owners with known holdings and known home addresses are targets for so-called "wrench attacks," physical assaults meant to force victims to hand over wallet passwords. TechCrunch reported that in the weeks following the ShipMonk breach, some customers received fake letters in the mail with QR codes designed to steal wallet backup passwords when scanned. Crypto hardware makers have had a rough stretch generally. Bitcoin Magazine noted that Ledger customers were targeted after its payment processor Global-e was compromised, and wallet provider SafePal disclosed a breach exposing nearly 40,000 customers' order information last month.
The fair criticism, and the limits of it Security researchers have a legitimate point here
hardware wallet companies built their entire pitch on being the secure, offline alternative to exchanges, yet they keep outsourcing core customer-facing functions, like email and shipping, to third-party vendors with their own security failures. That's a real structural weakness, not a hypothetical one. Two breaches in two months at one company is a pattern. Trezor isn't denying that. The company said it's reevaluating its vendor relationships and has warned customers their email addresses could be reused in future phishing attempts. That's a straightforward acknowledgment that the vetting process for Brevo and ShipMonk wasn't good enough the first time. Trezor hasn't released a dollar figure or a victim count for actual theft, only the click-through number before the domain was taken down. Whether this campaign resulted in significant losses, or was mostly caught before real damage was done, remains an open question the company hasn't answered.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.