A security warning sent through Trezor’s legitimate newsletter system turned out to be the attack itself.
Attackers exploited a breach at Brevo, the third-party email platform Trezor uses for newsletters, to send a fake alert claiming a hardware vulnerability could expose users’ wallet seeds. The email pushed recipients toward a malicious website and an application that requested their wallet backup.
The campaign reached 347,000 Trezor newsletter subscribers, and 2,500 people clicked the malicious link before Trezor intervened. The company said its products, infrastructure, and users’ cryptocurrency wallets were not compromised. However, the incident shows how breaching a trusted vendor can give attackers a direct route to a company’s audience.
How attackers weaponized legitimacy
Most phishing attacks start by obtaining a list of email addresses and then building a convincing imitation of the service they want to impersonate. In this case, the attackers skipped much of that work by compromising the legitimate email service Trezor already used to communicate with customers, then used that trusted channel to direct users toward a malicious platform.
According to Trezor, the attackers compromised its account at Brevo, one of 120 customer accounts affected at the email provider. That access allowed them to distribute the phishing message through Trezor’s legitimate newsletter channel, giving the campaign an advantage that a conventional spoofed email would not have.
The message itself was designed to create urgency. It claimed that Trezor devices were affected by a serious “STM32 Entropy Bug” that could expose users’ wallet seeds.

The legitimate delivery channel made the campaign especially dangerous. Rather than merely impersonating Trezor, the attackers delivered their message through infrastructure recipients already associated with the company while exploiting a particularly urgent fear: the exposure of a wallet recovery seed.
Another third-party compromise in weeks
Trezor said it disabled the compromised Brevo account within 20 minutes and worked to have the malicious domain taken down at the DNS level. The company has not reported any confirmed wallet theft from the campaign, and says users who only clicked without entering their wallet backup remain safe.
The Brevo compromise comes just weeks after a separate breach involving shipping provider ShipMonk. That incident reportedly exposed data belonging to approximately 81,000 customers across multiple cryptocurrency hardware-wallet companies, including around 14,000 Trezor customers. Leaked home addresses could increase the risk of targeted phishing, theft, or wrench attacks.
A wrench attack is a type of attack in which cybercriminals go physical, using threats or violence to force crypto holders to surrender access to their funds.
The pattern goes back to 2024, when attackers compromised another of Trezor’s third-party providers. Attackers accessed the support ticketing portal and stole data from roughly 66,000 users. BleepingComputer reported that attackers used the stolen information in phishing attempts designed to steal victims’ 24-word wallet recovery seeds.
Following the latest incident, Trezor said it was reviewing its “vendor relationships and security requirements,” putting its dependence on third-party providers under fresh scrutiny.
What Trezor users should do now
Trezor recommends that its users should:
- Not click any link asking for a wallet backup, as the company “will never contact you asking for your wallet backup.”
- Delete suspicious emails requesting a wallet backup. Users may also report them to Trezor through the contact options on its official website before deletion.
Trezor advises anyone who entered a wallet backup on the malicious site to immediately create a new wallet with a new recovery seed and transfer their funds to it.
However, these recommendations extend beyond crypto:
- Don’t click security links simply because they arrive from a familiar company.
- Verify them through the company’s official website or app.
- Use multifactor authentication for email, exchange, and other online accounts, while remembering that MFA cannot protect a wallet once its recovery phrase has been exposed.
- Treat recovery phrases, passwords, and other authentication secrets as information that should never be shared in response to an unsolicited request.
Companies also need to examine the vendors they trust. Enterprises should assess third-party security controls, limit vendor access, and prepare for incidents involving compromised communications platforms rather than treating vendor security as someone else’s problem.
Consumers should similarly consider more than a company’s own security claims. Its email, support, shipping, and customer-management providers may also hold information that attackers can exploit.
For both users and businesses, a message arriving through a legitimate channel should be treated as one trust signal — not proof that its instructions are safe.





