Trezor warns users after email provider Brevo breach exposes 347,000 subscribers to phishing
Email hack hits Trezor subscribers
Trezor, a maker of hardware wallets used to store crypto, is warning users about phishing emails following a breach of its email provider. The company said hackers gained access to the email domain managed by Brevo, a third-party service.
Trezor has since taken down the affected domain and launched an investigation. The company told Protos that about 347,000 newsletter subscribers were affected and that their email addresses are likely known to the attacker and could be used for targeted scams.
Scammers target wallet users with fake alerts
Soon after the breach was revealed, scammers began sending messages to Trezor subscribers. One widely reported message carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” These messages tried to trick users into giving up their wallet backup phrases, which are the codes needed to recover access to stored funds.
Trezor confirmed the alerts were not sent by the company. In a statement on X, the company warned: “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”
What Brevo held and what was safe
Trezor stressed that Brevo’s systems did not contain passwords, wallet data, or other personal information beyond the email addresses. The company also emphasized that no Trezor device or Trezor Suite software has ever exposed anyone’s keys or funds in its 12 years of operation.
“That is the part we control end to end, and it is the part that decides whether your BTC is safe,” the company said, referring to its own hardware and software security.
Other crypto firms also caught in the breach
Brevo is also the email provider for several other crypto companies, all of which have since warned their users about phishing attempts. Affected firms include BitBox, CoinTracking, Peach Bitcoin, and Blocktrainer.
Reports indicated that phishing campaigns using these brands tried various social engineering tactics. CoinTracking users were targeted with a fabricated breach claim, while BitBox subscribers received warnings about a microcontroller entropy bug similar to the one used against Trezor users.
Part of a rough few months for Trezor partners
The Brevo incident adds to a string of security issues involving Trezor’s third-party vendors this year. In August, the company disclosed that its shipping partner ShipMonk was breached, initially leaking the details of 13,689 customers. Trezor later revised that figure upward to more than 80,000 affected customers.
The company also learned that ShipMonk had not followed a promised 90-day data deletion policy. Trezor said it plans to reduce the amount of customer information held by partners and will review vendor relationships and security requirements.
Why this matters for wallet users
The incident highlights the risks of relying on third-party services for customer communication. While Trezor maintains that its core security remains intact, the exposure of email addresses gives attackers a direct channel to target users with convincing scams.
For wallet users, the practical takeaway is to remain cautious about unsolicited messages claiming urgent security issues and to never share recovery phrases or click on suspicious links.
What happens next
Trezor said it is investigating the Brevo breach. The company did not provide a timeline for the investigation or details on how the attackers gained access to the email domain.