Hardware crypto wallet manufacturer Trezor is issuing a second warning in recent months after one of its third-party service providers was compromised, potentially exposing customer data to malicious actors.
In a blog post published this week, Trezor revealed that a cyberattack on Brevo, a marketing technology platform the company uses to distribute newsletters, enabled hackers to dispatch approximately 347,000 phishing emails to Trezor customers. These messages contained a malicious link designed to impersonate communications from the wallet maker.
Clicking the link triggers the download of an application that prompts the victim to enter their wallet backup password. According to Trezor, one of the email subject lines used in the campaign read: “Critical Security Alert: STM32 Entropy Vulnerability.”
Once obtained, a stolen wallet password allows a hacker to irreversibly drain the victim’s funds on the public blockchain.
In an incident status update, Brejo confirmed that the attackers gained access to 138 Brevo accounts to distribute the phishing messages at scale. The company stated that the hackers exploited a misconfiguration that meant their access was “not properly scoped,” resulting in permissions that were “wrongly granted” across all organizations reachable by the compromised accounts.
The incident underscores a prevalent security challenge in which attackers compromise data held by third-party vendors essential to serving customers. Trezor emphasized that none of its products, wallets, or account systems were affected by the breach.
This marks the second breach affecting Trezor in recent weeks. In August, the company alerted customers that shipping partner ShipMonk had been compromised, exposing the names, phone numbers, email addresses, and postal addresses of at least 81,000 individuals who purchased Trezor hardware wallets.
The data exposure puts crypto owners and other high-net-worth individuals at risk of targeted violence, including so-called “wrench” attacks, which involve physical coercion to extract sensitive passwords.
In the weeks following the ShipMonk breach, some customers received physical letters bearing the Trezor name and containing QR codes. When scanned, these codes directed victims to fraudulent pages designed to capture their crypto wallet passwords.
Trezor said it is reevaluating its relationships with its vendors and cautioned customers that their email addresses may be used in future phishing campaigns.
Also Read
- How to watch Sabalenka vs Rybakina: US Open 2026 Women’s Final FREE Live Streams, TV Channels
- Semaglutide Reverses Key Aging Markers and Extends Lifespan in Landmark Mouse Study
- China’s Robotics Giant Aims to Replicate DJI’s Global Drone Dominance
- New AI Approach Mimics Pathologists’ Scanning Methods to Improve Cancer Detection


