Trezor customers hit by phishing attack after email provider breach exposes 347,000 addresses

Someone who owns a Trezor hardware wallet and thinks their crypto is safe because it’s offline should read this carefully. The device might be secure, but the company behind it keeps handing attackers a roadmap to its customers.

As TechCrunch reported, Trezor has confirmed that hackers breached Brevo, a marketing tech company Trezor uses to send newsletters, and used that access to fire off roughly 347,000 phishing emails to Trezor customers. The emails carried a malicious link. Click it, and you download an app that asks for your wallet backup password. Hand that over, and your funds are gone. There is no reversing a blockchain transaction, no fraud department to call.

One of the subject lines read: “Critical Security Alert: STM32 Entropy Vulnerability.” That kind of message is engineered to cause panic, and panic makes people click things they shouldn’t. The people behind this knew exactly what they were doing.

Brevo’s own account of the incident is worth reading closely. The company said hackers accessed 138 Brevo accounts and exploited a flaw where access was “not properly scoped,” meaning whoever got in could reach far more organizations than their credentials should have allowed. That is a serious access control failure, and it raises real questions about what Brevo considers adequate security for the companies that trust it with their customer lists.

But Trezor’s own track record here is also fair to question. This is the second breach in just a few weeks affecting the company’s customers. In August, Trezor alerted users that ShipMonk, one of its shipping partners, was compromised in a separate attack. That breach exposed names, phone numbers, email addresses, and physical home addresses for at least 81,000 people who bought Trezor hardware.

Physical addresses in the hands of criminals are not a minor data point. Crypto holders are increasingly targeted by so-called “wrench attacks,” where someone shows up in person and uses physical force or intimidation to extract wallet passwords. The combination of shipping records and phishing access gives bad actors both the location and the email address of potentially wealthy targets.

In the weeks after the ShipMonk breach, some Trezor users reportedly received letters in the post containing QR codes linking to fake Trezor pages designed to steal wallet credentials. The attacks are coordinated and they are escalating.

Trezor says none of its products or account systems were directly affected. That may be technically true, but it misses the point. The threat to customers does not require Trezor’s own systems to be compromised. It only requires that the web of third-party vendors surrounding Trezor have weak security. And right now, that web is not holding up well.

The company says it is reevaluating its vendor relationships and warned customers their email addresses may be used again in future attacks. That is the most honest thing Trezor has said through all of this. Customers should take it seriously.