Trezor confirmed on September 9 that Brevo, the third-party email platform it uses to send its newsletter, had been broken into and used to blast roughly 347,000 of its customers with a phishing email disguised as an urgent hardware security warning. The company says its wallets, accounts, and the funds inside them were never touched. The exposure was limited to a list of email addresses sitting in someone else's system.
That distinction matters, but so does the fact that this is the second time in two months a Trezor vendor has leaked customer data. In August it was a shipping partner. This time it's the company that sends its emails. Neither breach touched Trezor's own infrastructure, and both still put real customers at real risk, because attackers only need one weak link in a long vendor chain to reach a target that never let its guard down internally.
RelatedKDDI Breach Exposes 14M Users, Passwords in Plaintext
What actually happened at Brevo?
Brevo is a marketing-email platform, the kind of tool a company plugs in to run its newsletter without building that infrastructure itself. On September 9, an attacker got into 120 Brevo customer accounts, Trezor's among them, and used that access to send email as if it came from those companies' own addresses. For Trezor, that meant an email landing in inboxes from a domain and sender name subscribers already trusted, with a subject line built to sound like it came straight from the security team: "Critical Security Alert: STM32 Entropy Vulnerability."
STM32 is a real family of microcontrollers, and some hardware wallets, Trezor's included, do use them. Borrowing a real technical term is what made the lure work better than a generic "your account has been suspended" email would have. The email pushed recipients toward a download, an app that, once installed, asked for the wallet's backup phrase, the one string of words that can move every asset out of a hardware wallet regardless of PIN or device.
Why does a Brevo breach threaten a wallet nobody hacked?
Because the backup phrase is the actual key, and hardware wallets are built on the assumption that the device itself is the only thing that ever needs to see it. Trezor didn't get hacked in any technical sense here. Nobody breached its firmware, its servers, or its account system. What got compromised was trust in a familiar sender, which is a cheaper target than cryptography and just as effective if the victim types their phrase into the wrong place.
Brevo's side of the database held only email addresses pulled from newsletter sign-ups, according to Trezor, not passwords, wallet data, or other personal details. That's the good news. The bad news is an email address tied to "subscribes to a hardware wallet company's newsletter" is itself a target list: everyone on it is, by definition, a crypto holder worth phishing.
- About 347,000 Trezor newsletter addresses were exposed through the Brevo compromise.
- Roughly 2,500 people clicked the malicious link before Trezor took the domain down, within 20 minutes of discovery.
- Brevo said 120 of its customer accounts were accessed in total; BitBox, another hardware wallet maker, reported the same phishing pattern hitting its own newsletter subscribers.
- Trezor states no product, wallet, or account system was touched, and reiterates it will never ask for a backup phrase by email.
Who else got hit, and is this a Trezor problem or a Brevo problem?
It's a Brevo problem that happens to land hardest on Trezor's customers, because Trezor is a bigger, higher-value target than most Brevo clients. BitBox, a Swiss hardware wallet maker, confirmed its own newsletter subscribers received similar phishing mail through the same compromised platform. Reports also point to other bitcoin-adjacent businesses that use Brevo seeing the same pattern. The common denominator isn't the wallet brand, it's the vendor.
RelatedPixel 11 Loses MTE Security Support, GrapheneOS Confirms
| Company | What was exposed | Wallets/funds affected? |
|---|---|---|
| Trezor | ~347,000 newsletter emails via Brevo | No, per Trezor's statement |
| BitBox | Newsletter subscribers, same phishing template | No confirmed impact reported |
| Trezor (August, separate incident) | Names, phone numbers, addresses of ~81,000 people via shipper ShipMonk | No, shipping data only |
What's next for Trezor and its vendors?
Trezor says it's reevaluating its relationships with third-party vendors, which is the standard line after any supply-chain incident, but the underlying arithmetic doesn't change quickly. A hardware wallet company still needs to run a newsletter, still needs shipping partners, and every one of those integrations is a door that doesn't require breaking Trezor's own security to walk through. Expect more scrutiny on which vendors get access to customer contact data at all, and possibly a move toward in-house email infrastructure for security-sensitive companies more broadly. That's a real cost increase for a fairly mundane function, which is exactly why so many companies outsource it in the first place.
- Aug 2026ShipMonk, a Trezor shipping partner, discloses a breach exposing names, phone numbers, and addresses of about 81,000 people.
- Sep 9, 2026Attacker compromises 120 Brevo accounts, including Trezor's, and begins sending phishing email from Trezor's trusted sender identity.
- Sep 9, 2026Trezor detects the campaign and takes down the malicious domain within 20 minutes; about 2,500 recipients had already clicked.
- Sep 10-11, 2026Trezor publishes a public incident writeup; BitBox and other Brevo customers confirm parallel phishing waves.
Our take
This is a phishing story dressed up as a breach story, and that distinction should shape how seriously to take it. Nobody's Trezor got remotely compromised by malware or a firmware flaw. What happened is an attacker rented Trezor's own credibility for a few hours by hijacking a vendor's send capability, and it worked well enough that 2,500 people clicked. The 20-minute takedown is genuinely fast and worth crediting. But the deeper problem, a company's security reputation being only as strong as its weakest marketing vendor, isn't something a fast incident response fixes. It just limits the damage from the next one.
The practical lesson for anyone holding a hardware wallet from any brand: no legitimate wallet maker will ever ask for your backup phrase through email, a downloaded app, a website, or a phone call. That single rule, applied without exception, would have stopped this campaign cold regardless of how convincing the sender address looked.
- Vendor disclosures. Whether Trezor names Brevo alternatives or brings newsletter infrastructure in-house.
- Copycat campaigns. The 347,000-address list is now presumably circulating; expect reused templates against the same recipients from unrelated senders.
- BitBox and other Brevo clients. Watch for additional hardware wallet or crypto brands confirming they were affected by the same 120-account compromise.
- OfficialTrezor: Security incident at Brevo, our third-party email provider company statement, timeline, and scope
- ReportingTechCrunch independent confirmation and additional context
- ReportingBleeping Computer technical breakdown of the phishing chain
Original analysis by GenZTech. Source: Trezor.
