Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
Trezor says a cyberattack on Brevo, a marketing service it uses for newsletters, allowed attackers to send roughly 347,000 phishing emails to its customers containing a malicious link that downloads an app requesting the wallet backup password. Trezor reported this is the second recent vendor-related breach affecting its customers after a separate ShipMonk incident exposed purchaser contact and postal details.

Why It Matters
The incident underscores how compromises at third-party vendors can put cryptocurrency holders at immediate financial risk, since a stolen backup password can let attackers irreversibly drain funds on the public blockchain. It also compounds concerns about targeted physical threats and follow-on social engineering tied to previously leaked customer contact data.
Key Facts
- Phishing emails sent: Approximately 347,000
- Vendor breached: Brevo (marketing tech company)
- Brevo accounts abused: 138 accounts
- Example email subject line: "Critical Security Alert: STM32 Entropy Vulnerability."
- What the malicious link did: Downloaded an app that asked victims for their wallet backup password
Trezor warned customers that a cyberattack on Brevo, the marketing platform the hardware wallet maker uses to distribute newsletters, was used to deliver a large-scale phishing campaign. The company said attackers leveraged Brevo access to send about 347,000 emails to Trezor customers containing a link that, if opened, downloaded an application prompting users to provide their wallet backup password. Trezor emphasized that a compromised backup password can allow attackers to permanently steal funds on the public blockchain.
Brevo said the adversaries were able to use 138 of its accounts to dispatch the messages and attributed the mass-mailing to a flaw that left the attackers' access "not properly scoped." The vendor added that the access was "wrongly granted" to all organizations reachable by the compromised accounts, enabling the volume of phishing messages that impersonated Trezor.
This is the second vendor-related security incident to affect Trezor customers in recent weeks. In August, Trezor disclosed that the fulfillment partner ShipMonk had been breached, exposing names, phone numbers, email addresses, and postal addresses for at least 81,000 buyers of Trezor devices. That earlier leak has already been used in follow-up scams, including mailed letters purporting to be from Trezor that contained QR codes linking to fake pages designed to harvest wallet passwords.
Trezor said its own products, wallets, and account systems were not impacted by the Brevo incident and that it is reassessing its vendor relationships. The company warned customers that their email addresses could be reused in further phishing attempts and urged vigilance as attackers exploit third-party compromises to target cryptocurrency holders.
Keep Reading

Zodia Custody CEO Julian Sawyer steps down, becomes adviser

Albuquerque Bans Bitcoin ATMs, Giving Operators 45 Days to Remove Them

Metaplanet cuts executive reward pool by 41%, extinguishes $220 million in value
