Trezor confirmed on September 9 that Brevo, the third-party email platform it uses to send its newsletter, had been broken into and used to blast roughly 347,000 of its customers with a phishing email disguised as an urgent hardware security warning. The company says its wallets, accounts, and the funds inside them were never touched. The exposure was limited to a list of email addresses sitting in someone else's system.

That distinction matters, but so does the fact that this is the second time in two months a Trezor vendor has leaked customer data. In August it was a shipping partner. This time it's the company that sends its emails. Neither breach touched Trezor's own infrastructure, and both still put real customers at real risk, because attackers only need one weak link in a long vendor chain to reach a target that never let its guard down internally.

RelatedKDDI Breach Exposes 14M Users, Passwords in Plaintext

How the Brevo breach turned into a phishing campaign Flow diagram: attacker compromises 120 Brevo accounts, accesses Trezor's 347,000-address newsletter list, sends a fake STM32 vulnerability alert, victim clicks and is asked for their wallet backup phrase, Trezor takes the domain down within 20 minutes. ATTACKER Breaches 120 Brevo accounts NEWSLETTER LIST 347,000 Trezor subscriber emails FAKE ALERT "Critical Security Alert: STM32 Entropy Vulnerability" MALICIOUS APP Asks victim to type their wallet backup phrase RESPONSE Trezor kills the domain in 20 minutes, ~2,500 clicked genztech.blog
Fig 1 The attack didn't need to touch Trezor's own systems: a breach two steps removed from the product was enough to put a wallet-draining app in front of real customers.

What actually happened at Brevo?

Brevo is a marketing-email platform, the kind of tool a company plugs in to run its newsletter without building that infrastructure itself. On September 9, an attacker got into 120 Brevo customer accounts, Trezor's among them, and used that access to send email as if it came from those companies' own addresses. For Trezor, that meant an email landing in inboxes from a domain and sender name subscribers already trusted, with a subject line built to sound like it came straight from the security team: "Critical Security Alert: STM32 Entropy Vulnerability."

STM32 is a real family of microcontrollers, and some hardware wallets, Trezor's included, do use them. Borrowing a real technical term is what made the lure work better than a generic "your account has been suspended" email would have. The email pushed recipients toward a download, an app that, once installed, asked for the wallet's backup phrase, the one string of words that can move every asset out of a hardware wallet regardless of PIN or device.

Why does a Brevo breach threaten a wallet nobody hacked?

Because the backup phrase is the actual key, and hardware wallets are built on the assumption that the device itself is the only thing that ever needs to see it. Trezor didn't get hacked in any technical sense here. Nobody breached its firmware, its servers, or its account system. What got compromised was trust in a familiar sender, which is a cheaper target than cryptography and just as effective if the victim types their phrase into the wrong place.

Brevo's side of the database held only email addresses pulled from newsletter sign-ups, according to Trezor, not passwords, wallet data, or other personal details. That's the good news. The bad news is an email address tied to "subscribes to a hardware wallet company's newsletter" is itself a target list: everyone on it is, by definition, a crypto holder worth phishing.

  • About 347,000 Trezor newsletter addresses were exposed through the Brevo compromise.
  • Roughly 2,500 people clicked the malicious link before Trezor took the domain down, within 20 minutes of discovery.
  • Brevo said 120 of its customer accounts were accessed in total; BitBox, another hardware wallet maker, reported the same phishing pattern hitting its own newsletter subscribers.
  • Trezor states no product, wallet, or account system was touched, and reiterates it will never ask for a backup phrase by email.

Who else got hit, and is this a Trezor problem or a Brevo problem?

It's a Brevo problem that happens to land hardest on Trezor's customers, because Trezor is a bigger, higher-value target than most Brevo clients. BitBox, a Swiss hardware wallet maker, confirmed its own newsletter subscribers received similar phishing mail through the same compromised platform. Reports also point to other bitcoin-adjacent businesses that use Brevo seeing the same pattern. The common denominator isn't the wallet brand, it's the vendor.

RelatedPixel 11 Loses MTE Security Support, GrapheneOS Confirms

CompanyWhat was exposedWallets/funds affected?
Trezor~347,000 newsletter emails via BrevoNo, per Trezor's statement
BitBoxNewsletter subscribers, same phishing templateNo confirmed impact reported
Trezor (August, separate incident)Names, phone numbers, addresses of ~81,000 people via shipper ShipMonkNo, shipping data only

What's next for Trezor and its vendors?

Trezor says it's reevaluating its relationships with third-party vendors, which is the standard line after any supply-chain incident, but the underlying arithmetic doesn't change quickly. A hardware wallet company still needs to run a newsletter, still needs shipping partners, and every one of those integrations is a door that doesn't require breaking Trezor's own security to walk through. Expect more scrutiny on which vendors get access to customer contact data at all, and possibly a move toward in-house email infrastructure for security-sensitive companies more broadly. That's a real cost increase for a fairly mundane function, which is exactly why so many companies outsource it in the first place.

  1. Aug 2026ShipMonk, a Trezor shipping partner, discloses a breach exposing names, phone numbers, and addresses of about 81,000 people.
  2. Sep 9, 2026Attacker compromises 120 Brevo accounts, including Trezor's, and begins sending phishing email from Trezor's trusted sender identity.
  3. Sep 9, 2026Trezor detects the campaign and takes down the malicious domain within 20 minutes; about 2,500 recipients had already clicked.
  4. Sep 10-11, 2026Trezor publishes a public incident writeup; BitBox and other Brevo customers confirm parallel phishing waves.

Our take

This is a phishing story dressed up as a breach story, and that distinction should shape how seriously to take it. Nobody's Trezor got remotely compromised by malware or a firmware flaw. What happened is an attacker rented Trezor's own credibility for a few hours by hijacking a vendor's send capability, and it worked well enough that 2,500 people clicked. The 20-minute takedown is genuinely fast and worth crediting. But the deeper problem, a company's security reputation being only as strong as its weakest marketing vendor, isn't something a fast incident response fixes. It just limits the damage from the next one.

The practical lesson for anyone holding a hardware wallet from any brand: no legitimate wallet maker will ever ask for your backup phrase through email, a downloaded app, a website, or a phone call. That single rule, applied without exception, would have stopped this campaign cold regardless of how convincing the sender address looked.

What to watch
  • Vendor disclosures. Whether Trezor names Brevo alternatives or brings newsletter infrastructure in-house.
  • Copycat campaigns. The 347,000-address list is now presumably circulating; expect reused templates against the same recipients from unrelated senders.
  • BitBox and other Brevo clients. Watch for additional hardware wallet or crypto brands confirming they were affected by the same 120-account compromise.
Primary sources

Original analysis by GenZTech. Source: Trezor.