Trending: On-device modelsSearch
iHeartGeek
iTECH

Trezor Warns 347,000 Customers After Brevo Breach

Trezor says a breach at its email provider sent a malicious phishing campaign to 347,000 customers, putting crypto holders on high alert.

Trezor security warning artwork about the Brevo email-provider phishing incident; official artwork supplied by Trezor

Trezor has warned roughly 347,000 customers after hackers abused its newsletter provider to send a convincing phishing campaign. The emails claimed to be a critical security alert and tried to trick wallet owners into handing over the backup that protects their crypto.

According to Trezor and TechCrunch, the incident happened at Brevo, a third-party marketing platform used to send newsletters. Trezor said the attack did not compromise its products, wallets or account system, but the stolen mailing-list access was enough to put a large audience directly in front of scammers.

What's actually going on

Trezor said the attackers sent a malicious link from its account. The link prompted recipients to download an app and enter their wallet backup, while one subject line warned of a fictional “STM32 Entropy Vulnerability”. Trezor said the campaign reached 347,000 customers and that all of them were contacted about the risk.

TechCrunch reports that Brevo said attackers accessed 138 accounts after exploiting a flaw that left access improperly scoped. Trezor took down the phishing domain at the DNS level within 20 minutes, limiting access to people who clicked before the shutdown. The company said no passwords, wallet data or other personal information were held in Brevo’s system.

This is also the second recent breach involving a Trezor supplier. TechCrunch previously reported that a ShipMonk incident exposed the names, phone numbers, email addresses and postal addresses of at least 81,000 people who had bought Trezor hardware.

Why you should care

A newsletter breach can sound less frightening than a wallet hack, but that is exactly the trap. The attackers did not need to break Trezor’s hardware: they only needed a trusted-looking email and a believable panic button. Once a wallet backup is typed into a fake app or website, the blockchain does not offer a helpful “undo” button.

Trezor says customers should not click the links or provide personal information. Anyone who entered their wallet backup after following the phishing link should move their funds to a new wallet immediately. If the backup was only used on the Trezor device during recovery, the company says the assets remain secure.

Our opinion

Trezor’s core systems staying untouched is the good news; exposing hundreds of thousands of customers to a targeted wallet-stealing campaign is the grim footnote. The practical verdict is simple: treat every urgent wallet email as hostile, even when it appears to come from a familiar brand. Hardware wallets are not magic shields against social engineering, and this breach is a very expensive reminder to keep the backup offline and never type it into an email link’s mystery download.