Hardware wallet provider Trezor has alerted users after a breach at marketing firm Brevo led to hundreds of thousands of phishing emails aimed at stealing crypto recovery passwords.

  • Approximately 347,000 Trezor customers targeted via phishing emails due to a Brevo breach.
  • Attackers used fake security alerts to trick users into downloading malicious password-stealing apps.
  • This marks the second major third-party vendor compromise for Trezor in two months.

Hardware cryptocurrency wallet giant Trezor has issued an urgent warning to its user base for the second time in recent months. The company revealed that a cyberattack on Brevo, a marketing technology firm used by Trezor for newsletter distribution, has exposed its customers to a sophisticated phishing campaign.

According to a detailed blog post, hackers managed to send roughly 347,000 phishing emails to Trezor customers. These messages contained malicious links and used alarming subject lines such as "Critical Security Alert: STM32 Entropy Vulnerability" to create a sense of urgency. Upon clicking the link, users were prompted to download an application that requested their wallet backup password—the master key to their funds.

Why This Matters

BozokMedia analysis shows that this incident underscores the critical vulnerability of the 'trusted vendor' model. Even when a primary product like a hardware wallet is architecturally secure, the surrounding operational ecosystem (marketing, shipping, CRM) can be weaponized to target high-net-worth individuals. This shifts the security perimeter from the device to the user's digital identity.

"In the realm of non-custodial wallets, the human element remains the weakest link; no amount of hardware encryption can protect a user who voluntarily hands over their seed phrase."

Brevo admitted that hackers accessed 138 of its accounts to facilitate the mass mailing. The company attributed the breach to a flaw where access was "not properly scoped," meaning hackers were wrongly granted permissions to reach organizations they should not have had access to. Trezor has emphasized that its own internal systems and product firmware remain uncompromised.

This follows a troubling pattern for the company. In August, Trezor warned that its shipping partner, ShipMonk, suffered a breach that leaked the personal details—including names and home addresses—of 81,000 customers. This specific leak is particularly dangerous as it enables "wrench attacks," where criminals use physical threats to extort passwords from known crypto holders.

Incident Affected Vendor Users Impacted Primary Threat
Recent Breach Brevo (Marketing) ~347,000 Digital Phishing/Password Theft
August Breach ShipMonk (Shipping) ~81,000 Physical Doxing/Wrench Attacks
Did You Know?: A 'Wrench Attack' is a slang term in the crypto community for a physical assault where a criminal uses force to compel a victim to reveal their private keys or passwords.

Frequently Asked Questions

Q1: Was my Trezor device actually hacked?
No. The breach occurred at a third-party marketing company (Brevo), not within Trezor's hardware or core software systems.

Q2: What should I do if I clicked the link?
If you entered your backup password, your funds are at immediate risk. You must transfer your assets to a new wallet with a new seed phrase immediately.