Trezor Warns 347,000 Customers After Brevo Hack — SkimNews

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Trezor disclosed that a hack of Brevo, a marketing tech firm it uses to send newsletters, let attackers send ~347,000 phishing emails to its customers with malicious links posing as security alerts
- Brevo said hackers compromised 138 of its accounts due to an access flaw that was "not properly scoped," wrongly granting the attackers reach across every organization those accounts could access
- The phishing emails carried a link that, when tapped, downloaded an app requesting the victim's wallet backup password — a credential that enables irreversible theft of on-chain funds; one subject line read "Critical Security Alert: STM32 Entropy Vulnerability"
- Trezor stressed none of its own products, wallets, or account systems were affected, but warned customers their email addresses may fuel further phishing campaigns and said it is reevaluating its vendor relationships
- The Brevo breach is Trezor's second vendor-side incident in weeks: in August, shipping partner ShipMonk was compromised, exposing names, phone numbers, emails, and postal addresses of at least 81,000 Trezor hardware wallet buyers
- Physical-world risk is now in play — after the ShipMonk breach, some customers received mailed letters impersonating Trezor with QR codes linking to fake pages that harvest wallet passwords, raising the specter of "wrench" attacks targeting wealthy crypto holders
Why it matters: Trezor's customers are now exposed through two separate third-party vendors within weeks — roughly 428,000 total across Brevo and ShipMonk — and the leaked data (including postal addresses) puts wealthy crypto holders at risk of both digital phishing and physical coercion attacks, meaning Trezor must demonstrate it can secure its supply chain or lose the trust argument that distinguishes it from software wallets.
Ask SkimNews




