Technology
TechCrunch

Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

Source Entity

Zack Whittaker

September 13, 2026
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

A security breach at marketing platform Brevo allowed hackers to target 347,000 Trezor subscribers with phishing emails. The attack aimed to steal hardware wallet recovery phrases, posing a severe risk to user funds.

The Brevo Security Breach: A Massive Phishing Campaign

A significant cybersecurity incident has compromised the security of hardware wallet users after a flaw in the login system of marketing platform Brevo was exploited. This breach allowed unauthorized access to 138 client accounts, facilitating a large-scale phishing campaign. Most notably, approximately 347,000 Trezor newsletter subscribers received fraudulent communications disguised as legitimate security alerts from the hardware wallet manufacturer.

Mechanics of the Attack

According to Brevo’s internal postmortem, the attacker leveraged a vulnerability in their login system to gain entry. Once inside, they utilized six specific accounts to disseminate phishing emails. Beyond the unauthorized messaging, the attacker exported contact lists from 43 accounts, while another 93 accounts showed no suspicious activity. This breach did not only impact Trezor; other prominent crypto-sector entities, including BitBox and CoinTracking, were also utilized as vectors for similar fraudulent messages.

The Trezor Phishing Strategy

The phishing emails sent to Trezor subscribers were highly deceptive, utilizing the subject line “Critical Security Alert: STM32 Entropy Vulnerability” to create a false sense of urgency. When recipients clicked the provided link, they were prompted to download a malicious application. The primary goal of this software was to extract the victim's wallet backup password—the critical seed phrase required to authorize transactions and access assets on the public blockchain.

Broader Implications for Hardware Wallet Security

This incident marks the second time in as many months that Trezor has been forced to warn customers about a data breach involving a third-party service provider. While the hardware wallets themselves remain secure, the reliance on external marketing tech companies creates a significant attack surface. By compromising the communication channel, attackers can bypass traditional security skepticism, as users are conditioned to expect emails from their service providers.

Risks and Future Outlook

Trezor has advised that all 347,000 affected email addresses must be treated as compromised and potentially reusable for future phishing attempts. This highlights a growing trend in the cryptocurrency ecosystem where attackers focus on social engineering and supply chain vulnerabilities rather than attempting to crack encrypted hardware. As security awareness grows, users must remain vigilant against unsolicited requests for recovery passwords, remembering that legitimate hardware wallet manufacturers will never ask for such information via email or third-party applications.

Multiple Citing Sources

Verification Required?

Read the full report from the primary source

Go to TechCrunch