Trezor, a manufacturer of cryptocurrency hardware wallets, has issued a second warning to its users within two months following a security breach at a third-party partner that exposed customer information.
According to a recent blog update, the device maker revealed that attackers compromised Brevo, an email marketing vendor employed by Trezor. This breach enabled bad actors to dispatch roughly 347,000 deceptive phishing emails to clients, disguised as official communications from Trezor.
Clicking the embedded link prompts the download of a rogue application designed to steal the user’s wallet recovery seed. Trezor noted that at least one phishing variant carried the subject line: “Critical Security Alert: STM32 Entropy Vulnerability.”
Obtaining this secret seed allows attackers to drain the victim’s digital assets from the blockchain permanently.
Detailed in an official incident report, Brevo stated that intruders compromised 138 accounts to broadcast the spam campaign. The service provider explained that attackers exploited a configuration flaw involving permissions that were “not properly scoped,” which mistakenly granted them elevated access across multiple customer organizations.
This event underscores a growing trend of supply-chain security threats, where criminals target external contractors managing retail or operational workflows. Trezor clarified that its internal systems, core software, and hardware products remained entirely untouched.
The event follows another recent security breakdown for Trezor. Just last month, the firm disclosed that a logistics provider had been hit by a security breach. That breach at fulfillment service ShipMonk leaked the physical addresses, names, phone numbers, and email accounts of over 81,000 customers who ordered hardware devices.
Exposing such sensitive information creates serious security risks for cryptocurrency investors, leaving them vulnerable to targeted physical threats and “$5 wrench attacks” where criminals use coercion or violence to force victims to surrender access codes.
Since the ShipMonk incident, several customers reported receiving fraudulent physical letters pretending to be official correspondence from Trezor. These letters contained QR codes leading to fraudulent websites designed to siphon off recovery phrases.
Trezor indicated it is reviewing its third-party service agreements while cautioning clients to remain vigilant, as compromised email addresses could be targeted in subsequent phishing schemes.
