Trezor, the hardware wallet maker, is sounding the alarm after a breach at its email marketing provider led to a massive phishing campaign targeting its user base. Around 347,000 Trezor customers were emailed malicious links posing as official alerts, some of which prompted recipients to enter their wallet backup password— a move that could allow attackers to steal funds irreversibly from victims’ wallets once password and other credentials are leaked.
In a recent security update, Trezor revealed that Brevo, the service used to send its newsletters, was compromised. Hackers gained access to 138 Brevo accounts and leveraged improperly scoped permissions to reach multiple organizations, including Trezor, sending out deceptive emails claiming vulnerabilities like an “STM32 Entropy Vulnerability” to lure users into downloading a malicious application.
It’s important to note that the breach did not affect Trezor’s core systems—none of its wallets, hardware, or account platform were infiltrated. The danger comes from social engineering and phishing, not from exploiting firmware or device vulnerabilities.
Second Incident in Weeks
This is the second issue Trezor has faced in recent weeks. In August, the company disclosed a separate breach affecting its fulfillment partner, ShipMonk. That incident exposed personal data—names, postal and email addresses, and phone numbers—for at least 81,000 individuals who purchased Trezor wallets.
Following the ShipMonk breach, some people reported receiving letters impersonating Trezor, complete with QR codes that link to fake web pages attempting to steal wallet passwords. These kinds of “wrench attacks,” where criminals use physical threats to coerce someone into revealing credentials, are highlighted as real risks when personal data is leaked.
Trezor Responds, Users Advised
In response, Trezor says it will reevaluate vendor relationships to ensure stricter oversight and warns customers to be on guard. Specifically, users are cautioned that email addresses in Brevo’s databases may be used again in future phishing attempts. Always double-check links, be cautious of unexpected password requests, and use official channels for verification.
Vendors like Brevo face scrutiny too: it acknowledged the breach in its incident report, stating the access granted to accounts was improperly scoped, giving attackers more reach than should have been allowed.
While no direct losses due to the Brevo incident have been reported yet, the malicious emails represent a potent threat, as they ask for wallet backup passwords. Since wallets operate on public blockchains, once a password is compromised, the funds can be taken with no possibility of reversal.
This episode adds to growing concerns about supply chain and third-party security risks in the crypto space, especially for companies with strong reputations in hardware security. Leaked personal data, vendor misconfigurations, and phishing schemes continue to be prime security challenges in the broader crypto ecosystem.
What this means:This isn’t just a Trezor problem. Every crypto user must treat personal information exposure—especially through third parties—as a gateway to potentially catastrophic loss. Watch your inbox, validate every password request, and treat any link with suspicion. Vendors handling sensitive crypto-adjacent data need to learn: improper access controls don’t just risk privacy, they risk your assets.