On September 10, hardware wallet maker Trezor warned customers worldwide that a Brevo breach enabled crypto phishing, with attackers abusing compromised email accounts to send around 347,000 malicious messages to steal wallet backup information through convincing security alerts online.
The incident did not compromise Trezor’s wallets or internal systems. Instead, it exposed a different weakness: companies can secure their own technology while remaining vulnerable through the outside services they depend on to communicate with customers.
Trusted Email Infrastructure Turned Against Users
Brevo, the marketing technology provider used by Trezor, said attackers exploited a weakness in its SAML single sign-on system. The incident raises bigger questions about hardware wallet security, because protecting private keys alone cannot prevent criminals from using stolen customer information to build convincing attacks.
According to Brevo, attackers accessed 138 customer accounts. Six were used to send malicious messages, while contacts were exported from 43.
The company said access had been not properly scoped, allowing attackers to reach organizations they should not have been able to access. The breach gave criminals an unusually powerful tool for crypto phishing: access to legitimate company communication systems.
Messages sent through trusted infrastructure can appear more believable than emails coming from newly created or suspicious domains.
Trezor customers received a phishing email titled “Critical Security Alert: STM32 Entropy Bug Identified.” The message claimed that a flaw in STM32 microcontrollers could weaken how recovery phrases were generated and potentially expose users to attacks.
The message warned of “insufficient randomness in recovery phrase generation” and claimed some recovery seeds could have very low entropy. Recipients were then directed toward software that asked them to provide sensitive wallet backup information.
That method turned the campaign into a potential crypto wallet scam, because anyone who gives attackers a recovery phrase can lose control of their funds. Cryptocurrency transfers made using stolen credentials are generally difficult or impossible to reverse.
The effectiveness of this type of crypto phishing comes from trust. Users may normally look for fake addresses or badly written messages, but those warning signs become less useful when attackers operate through technology belonging to a legitimate provider.
Third-Party Breaches Expand the Risk
The Brevo incident was also a supply chain attack, showing how criminals can target a service provider instead of directly breaking into the company whose customers they ultimately want to reach.
It was not the first recent case of Trezor phishing connected to compromised customer information. In August, shipping partner ShipMonk suffered a breach that exposed names, phone numbers, email addresses and postal addresses belonging to at least 81,000 Trezor customers.
Some customers later received physical letters carrying QR codes that opened fake websites. That approach created another form of crypto wallet scam, moving the attack beyond inboxes and into victims’ homes.
The new Brevo campaign highlights the way crypto phishing can evolve when attackers combine leaked personal information with trusted digital services. Other cryptocurrency companies using Brevo, including CoinTracking and BitBox, also confirmed that their customers received malicious messages.
A second phishing email campaign targeting CoinTracking customers claimed users needed to refresh their API keys after a supposed data breach, again using urgency to push recipients toward a malicious link. Trezor said it is now reviewing its relationships with outside providers.
The company also warned that exposed addresses could be reused in future Trezor phishing campaigns as criminals continue building more targeted messages.
The incidents underline a larger challenge for crypto phishing defenses: protecting the wallet is only one part of protecting its owner. Email services, shipping partners and customer databases can all become indirect paths toward the same valuable target.
Inside Telecom provides you with an extensive list of content covering all aspects of the tech industry. Keep an eye on our Intelligent Tech sections to stay informed and up-to-date with our daily articles.
