- Trezor‘s third-party email partner Brevo was breached, exposing 347,000 newsletter subscribers’ email addresses.
- Hackers used the compromised domain to send phishing emails claiming a “Critical Security Alert: STM32 Entropy Vulnerability” to trick users into revealing wallet backups.
- Other crypto firms using Brevo, including BitBox, CoinTracking, Peach Bitcoin, and Blocktrainer, also warned users of phishing attempts.
- This incident follows a previous breach of Trezor’s shipping partner ShipMonk, which affected over 80,000 customers.
- Trezor stressed that no device or software has exposed user keys or funds in 12 years.
Trezor is grappling with yet another security incident after its third-party email partner Brevo was breached, exposing roughly 347,000 newsletter subscribers to potential phishing attacks. The wallet maker revealed that Hackers accessed its email domain, which has since been taken down, and that an investigation is underway.
Trezor told Protos that the affected email addresses are likely “known to the attacker and possibly reusable for phishing.” However, it stressed that “Brevo’s system holds no passwords, wallet data, or other personal information.”
Scammers warned newsletter subscribers of a “Critical Security Alert: STM32 Entropy Vulnerability” before trying to convince them to give up their wallet backups. Meanwhile, other crypto firms using Brevo—including BitBox, CoinTracking, Peach Bitcoin, and Blocktrainer—also warned users to be wary of phishing emails.
CoinTracking phishing attempts used a fabricated breach to trick users, while BitBox phishing attempts warned of a microcontroller entropy bug. This incident follows an August breach of Trezor’s shipping partner ShipMonk, which initially leaked 13,689 customer details—later revised to over 80,000.
Trezor told Protos that despite these two third-party data incidents, “What has not happened, in 12 years, is a Trezor device or Trezor Suite exposing anyone’s keys or funds.” It added that it will reduce customer information held by partners and review vendor security requirements.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
