Trezor warns customers after email provider Brevo breach enables mass phishing attack

Hardware wallet maker hit by second third-party incident in two months, exposing crypto owners to scams and physical risks

edit
By LineZotpaper
Published
Read Time2 min
Hardware crypto wallet maker Trezor has warned customers that a cyberattack on its third-party email provider, Brevo, allowed hackers to send around 347,000 phishing emails targeting Trezor users, marking the second such incident in as many months following a breach at shipping partner ShipMonk.

Trezor confirmed in a blog post this week that an attack on Brevo, a marketing technology company it uses to send newsletters, enabled hackers to send a large volume of phishing emails to customers. The emails carried a malicious link that, when opened, downloads an app asking for the victim's wallet backup password. One subject line read: "Critical Security Alert: STM32 Entropy Vulnerability." If obtained, the password can be used to irreversibly steal the customer's cryptocurrency funds on the public blockchain.

Brevo stated in an incident report that hackers accessed 138 accounts to send the phishing messages, abusing a flaw that caused their access "not to be properly scoped," resulting in permissions being "wrongly granted" to all reachable organisations. Trezor emphasised that none of its products, wallets, or accout system were directly affected.

This follows a data breach in August at Trezor's shipping partner ShipMonk, which exposed the names, phone numbers, email addresses, and postal addresses of at least 81,000 people who purchased Trezor hardware. Since then, some individuals have received physical letters claiming to be from Trezor, containing a QR code that leads to a fake page designed to steal wallet passwords. The combination of exposed personal data and crypto ownership puts victims at risk of targeted violence, including so-called "wrench attacks" where attackers use physical force to extract passwords.

Trezor said it is reevaluting its relationships with vendors and warned customers that their email addresses may be used again in future phishing attempts.

§

Analysis

Why This Matters

  • Crypto wallet owners face increased phishing and physical threats as third-party data exposure becomes a repeating issue
  • The incident highlights the vulnerability of relying on multiple vendors for customer communications and order fulfilment
  • Affected users may be targeted repeatedly by scammers who now possess their contact details and know they hold cryptocurrency

Background

Hardware wallets are devices designed to store cryptocurrency private keys offline, providing security against online theft. However, if a user's backup password (seed phrase) is compromsed, funds on the public blockchain can be stolen irreversibly, regardless of the hardware's integrity. Third-party data breaches are a common vector for such attacks, as severs like Trezor intentionally limit access to customer lists but must share data with service providers. The recent spate of breaches involving crypto companies has raised concerns about the security of the supply chain, especially for companies that market to high-value or high-profile asset holders.

Key Perspectives

Trezor (the affected company): Urges users to be vigilant and confirms it is reevaluating vendor relationships. Emphasises that its core products and account system remain uncompromised. Brevo (the breached provider): Acknowledges the incident and states that access was wrongly scoped, allowing the attack to reach multiple organisations. Critics/Skeptics: Some security observers note that two major third-party breaches in two months suggest systemic issues with Trezor's vendor manaagement. Others point out that phishing attacks requiring a user to download and run an app remain easier to avoid if users exercise caution, but the combination with physical letters and the number of exposed contacts escalates the real-world danger.

What to Watch

  • Whether Trezor publishes a list of affected customers or offers credit monitoring/byorst protection services
  • Any regulatory updates from data protection authorities regarding mandatory breach notification requirements for crypto companies
  • Potential class-action lawsuits from customers who suffered financial losses due to the phishing campaign
  • If the Brevo flaw is exploited again against other organisations using the same marketing platform

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.