Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Trezor warns users of phishing attack after third-party email provider breach
00

Trezor warns users of phishing attack after third-party email provider breach

Sep 9, 2026

Hardware wallet maker Trezor warned users on September 9, 2026, of a highly convincing phishing campaign sent from its legitimate domain. Attackers exploited an authorization vulnerability in email platform Brevo to access 138 client accounts, sending a fake "STM32 Entropy Vulnerability" alert to 347,000 Trezor subscribers. The breach also affected other crypto firms using Brevo, including BitBox and CoinTracking. While Trezor devices and funds remain secure, the incident marks Trezor's third vendor failure in four weeks.

Brevo email platform breach

  • ▪An attacker exploited a login system vulnerability in email platform Brevo to access 138 client accounts, enabling unauthorized phishing campaigns
  • ▪Brevo stated that the attacker created an account, enabled single sign-on, and invited legitimate users, which bypassed an authorization boundary to grant access to other organizations
  • ▪Brevo reported that six compromised accounts were used to send phishing emails, contacts were exported from 43 accounts, and 93 accounts showed no meaningful activity

STM32 entropy phishing campaign

  • ▪Trezor warned users on September 9, 2026, about a fraudulent phishing email titled "Critical Security Alert: STM32 Entropy Vulnerability" sent via its compromised email provider
  • ▪The phishing email falsely claimed that Trezor engineers discovered a design defect in STM32 microcontrollers that could leave recovery phrases with insufficient randomness
  • ▪The fraudulent Trezor email was sent to approximately 347,000 newsletter subscribers, and about 2,500 people accessed the malicious link before Trezor disabled the domain

Email authentication bypass

  • ▪Bitcoin security researcher Jameson Lopp noted that the malicious emails did not appear to be spoofed because they were sent directly through the compromised email provider
  • ▪The phishing emails originated from Trezor's legitimate sending infrastructure, displaying the sender address help@trezor.io and passing SPF, DKIM, and DMARC authentication checks
  • ▪Trezor's Brevo account stored only opt-in newsletter email addresses, and no passwords, wallet data, or other personal customer information were exposed in the breach

Trezor vendor security incidents

  • ▪An August 2026 breach at Trezor's shipping partner ShipMonk exposed the personal details of 80,689 customers, including names, phone numbers, and shipping addresses
  • ▪Trezor stated that despite third-party partner data leaks, no Trezor hardware device or Trezor Suite software has exposed user keys or funds in 12 years
  • ▪The Brevo breach represents Trezor's third vendor-related security incident within a four-week period in August and September 2026

Multi-firm phishing exposure

  • ▪Swiss hardware wallet maker BitBox reported that its newsletter subscriber list was targeted with a similar phishing campaign sent through its compromised Brevo account
  • ▪Crypto portfolio tracking and tax-reporting platform CoinTracking reported that its Brevo account was used to distribute a fake data breach notice urging users to refresh API keys
  • ▪Other cryptocurrency platforms utilizing Brevo, including Peach Bitcoin and Blocktrainer, also warned their users to be cautious of potential phishing attempts

Debatable claims

  • ▪Third-party data leaks undermine the security of crypto hardware wallets
  • ▪Trezor should self-host its customer communication and shipping infrastructure

10 sources

Bitcoin Magazine
Trezor Reveals Another Data Breach
View source article
Cointelegraph
Brevo Login Breach Affected Trezor, BitBox and CoinTracking
View source article
The Block
Trezor says third-party security breach led to phishing emails from legitimate domain
View source article
Unchained
Trezor Says Third-Party Email Breach Let Attackers Send Phishing From Its Own Domain - Unchained
View source article
Cointelegraph
Fake Security Emails Target Trezor and BitBox Users
View source article

Featured stories

View more in Bitcoin wallets & custody

US accuses Chinese AI firms of industrial-scale theft of AI technology

Sep 8, 2026 · 2 sources

Story comments

Loading comments…

Related Projects

Trezor

Topics

Bitcoin wallets & custodyCrypto privacy & surveillance

Featured stories

View more in Bitcoin wallets & custody

US accuses Chinese AI firms of industrial-scale theft of AI technology

Sep 8, 2026 · 2 sources