Hardware wallet maker Trezor warned users on September 9, 2026, of a highly convincing phishing campaign sent from its legitimate domain. Attackers exploited an authorization vulnerability in email platform Brevo to access 138 client accounts, sending a fake "STM32 Entropy Vulnerability" alert to 347,000 Trezor subscribers. The breach also affected other crypto firms using Brevo, including BitBox and CoinTracking. While Trezor devices and funds remain secure, the incident marks Trezor's third vendor failure in four weeks.
Story comments
Loading comments…