Hardware cryptocurrency wallet manufacturer Trezor has issued a second security warning in two months after confirming that a third-party vendor suffered a cyberattack. The company revealed that hackers exploited a vulnerability at Brevo, its marketing technology partner responsible for sending newsletters, to distribute approximately 347,000 phishing emails to Trezor customers.
According to a blog post published this week, the malicious messages contained links designed to download an application requesting the victim’s wallet backup password. One reported subject line read, “Critical Security Alert: STM32 Entropy Vulnerability.” Trezor cautioned that if attackers obtain this password, they can irreversibly drain funds from the individual’s public blockchain wallet.
Brevo stated in an incident report that the breach involved 138 compromised accounts. The firm attributed the vulnerability to improperly scoped access rights, noting that permissions were wrongly granted to all organizations reachable by the hackers’ accounts. Despite the exposure of customer contact information, Trezor emphasized that its proprietary products, wallets, and internal account systems remained uncompromised.
This incident follows a separate data leak from August involving ShipMonk, a shipping partner used by Trezor. That breach exposed personal details—including names, phone numbers, email addresses, and postal addresses—of at least 81,000 individuals who had purchased hardware wallets. Trezor warned that such personal data could make owners targets for physical threats, commonly referred to as “wrench attacks,” where criminals use force to extract passwords.
Following the ShipMonk leak, some recipients reported receiving physical mail containing QR codes that directed users to fake websites attempting to harvest wallet credentials. In response to both security failures, Trezor announced it is reevaluating its vendor relationships and urged customers to remain vigilant, as their email addresses may continue to be used for future fraudulent campaigns.
Trezor should refund people for this mess. You’re supposed to be the security standard, not just another link in the supply chain.
It’s terrifying that my physical address was leaked too. Can you imagine a wrench attack at your door? I feel exposed.
That subject line about the STM32 vulnerability is clever malware social engineering. But seriously, did Brevo really have access to all customer data?
Three breaches in six months? I’m rethinking this hardware wallet. Maybe air-gapped computers are the real answer for now.