Key Takeaways
- A security incident at email provider Brevo allowed attackers to send a fraudulent Trezor security alert to approximately 347,000 newsletter subscribers.
- About 2,500 recipients clicked the malicious link before Trezor took the associated domain offline within 20 minutes, while no Trezor wallets, devices or internal systems were compromised.
- The incident highlights a growing third-party security risk for crypto companies, where compromised communications infrastructure can make phishing campaigns appear legitimate even without direct access to customer assets.
A breach at Brevo, the third-party email marketing platform used by Trezor, enabled attackers to distribute a fraudulent security alert to roughly 347,000 Trezor newsletter subscribers. The incident illustrates a broader cybersecurity challenge for digital-asset companies: as crypto infrastructure becomes more institutionalized, attackers are increasingly targeting the communication and service providers surrounding wallets and exchanges rather than attempting to breach the underlying blockchain or custody systems.
347,000 Subscribers Targeted Through Legitimate Infrastructure
The phishing campaign was distributed on September 9 under the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” The message falsely claimed that a vulnerability affecting Trezor hardware could compromise wallet backups and directed recipients toward a malicious application designed to obtain sensitive wallet information.
Trezor said approximately 347,000 addresses received the initial email. The company disabled the relevant domain at the DNS level within 20 minutes, but approximately 2,500 people had clicked the malicious link before the shutdown. That represents less than 1% of the targeted audience, but the financial consequences for even a small number of successful wallet-backup disclosures could be significant.
The campaign was particularly credible because attackers gained access to legitimate email infrastructure rather than relying solely on a spoofed sender.
Third-Party Risk Moves to the Center of Crypto Security
Brevo said the security incident affected 120 customer accounts and that an unauthorized actor used access to send phishing emails from multiple accounts. Trezor subsequently suspended its Brevo account and disabled further email distribution.
The distinction between the breached provider and Trezor’s own infrastructure is important. Trezor said no wallet, product, account system or internal platform was compromised, and that Brevo did not store wallet passwords or recovery phrases.
However, approximately 347,000 email addresses are being treated as potentially known to the attacker and could be used in subsequent phishing campaigns. This creates a longer-term risk even after the original malicious domain has been removed.
Why Authentication Alone Is No Longer Enough
The incident demonstrates why conventional email-security signals can be insufficient in targeted crypto attacks. When attackers obtain access to an authorized sending platform, messages can originate from legitimate infrastructure and appear substantially more credible than conventional impersonation attempts.
That changes the behavioral equation for users. A professional-looking security notice sent through an established domain can bypass the skepticism normally applied to unfamiliar addresses, particularly when it references a technical vulnerability and creates an urgent reason to act.
The episode also follows a separate Trezor-related data exposure involving its logistics provider, which affected more than 80,000 customers. The combination increases the potential value of customer information for targeted social-engineering campaigns.
Strategic Outlook for Self-Custody Security
The Brevo incident reinforces that crypto security extends beyond private keys, hardware and blockchain protocols. As wallet providers rely on increasingly complex networks of marketing, logistics, cloud and communications vendors, third-party access becomes an important component of the overall threat surface. For the industry, stronger vendor controls, tighter authentication and faster incident response will become increasingly important as attackers seek to exploit trusted infrastructure rather than the cryptographic foundations of digital assets.
Comparison, examination, and analysis between investment houses
Leave your details, and an expert from our team will get back to you as soon as possible