Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider — SkimNews

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Trezor warned customers that a cyberattack on its email provider Brevo enabled hackers to send approximately 347,000 phishing emails impersonating the wallet maker, using subject lines like "Critical Security Alert: STM32 Entropy Vulnerability."
- Brevo disclosed that hackers compromised 138 of its accounts via a flaw where access was "not properly scoped" and "wrongly granted" across organizations the hackers' accounts could reach.
- The phishing link downloaded an app that asked victims for their wallet backup password — which, per Trezor, lets a hacker irreversibly steal funds on the public blockchain.
- This marks Trezor's second vendor breach in two months — in August, shipping partner ShipMonk was compromised, exposing names, phone numbers, emails, and postal addresses of at least 81,000 Trezor customers.
- Following the ShipMonk breach, some customers received physical mail letters impersonating Trezor with QR codes linking to fake phishing pages designed to steal wallet passwords.
- Trezor emphasized that none of its products, wallets, or account systems were directly compromised, and said it is reevaluating its vendor relationships while warning customers their emails may fuel future phishing attempts.
Why it matters: The Brevo breach exposed roughly 347,000 Trezor customer emails to phishing lures that can drain crypto wallets irreversibly, and combined with the August ShipMonk breach of 81,000+ customers, attackers now have multiple vectors — email and physical mail with QR codes — to target the same pool of crypto holders, potentially exposing them to both digital theft and physical "wrench" attacks.
Ask SkimNews




