Trezor customers spent this week deleting emails that looked like they came straight from the company: official sender address, familiar branding, and a subject line built to trigger panic. The hardware wallet maker has now confirmed that a breach of its third-party email provider let attackers send roughly 347,000 phishing messages from its own domain, part of a scam that has hit crypto owners across the globe since September 9, 2026. The incident, first reported by TechCrunch and confirmed in detail by BleepingComputer and The Register, is the latest sign that crypto hardware makers remain only as secure as the vendors plugged into their marketing stack.
What makes this campaign notable isn’t the phishing itself, phishing crypto owners is not new, it’s the delivery method. Because the emails went out through Trezor’s own newsletter infrastructure, they landed in inboxes with a legitimate sender address attached ([email protected]), skipping past the usual “this looks like a stranger” red flags that trained users rely on. That single detail turned an otherwise generic scam into one of the more convincing crypto phishing runs of 2026.
What Trezor confirmed about the breach
According to Trezor’s own public statement, posted to social media on September 9 and quoted by BleepingComputer, the company said: “Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.” The statement is archived on Trezor’s official X account.
Trezor said it moved fast once the campaign was spotted. In the same statement, the company said: “We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.” Reporting from BleepingComputer adds that Trezor also acted on the vendor side, saying: “No other Trezor system was touched. We have suspended the Brevo account to stop further email distribution.”
The identity of the breached vendor is where reporting has moved fastest. Trezor’s own initial statement did not name a provider, but multiple outlets, including The Register and KuCoin’s news desk, have since tied the incident to Brevo, the email marketing platform Trezor uses to run its newsletter. Trezor itself said, per BleepingComputer’s reporting: “On September 9, 2026, Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts.” That figure sits close to KuCoin’s separate count of 138 affected Brevo accounts, a gap the outlets have not yet reconciled.
The STM32 entropy lure, dissected
The phishing email’s hook was specific enough to feel technical, which is exactly the point. Titled “Critical Security Alert: STM32 Entropy Vulnerability,” the message claimed a hardware flaw in the STM32 microcontrollers used inside Trezor devices could expose users’ seed phrases to brute-force cracking. STM32 chips are real components used across the hardware wallet industry, not a Trezor invention, which is part of what made the lure land. Recipients were pushed toward a fraudulent app and asked to enter their wallet backup phrase to “verify” their device was safe.
That’s the tell every hardware wallet owner should have memorized by now: no legitimate wallet maker will ever ask for a seed phrase, in an app, on a website, or over email, under any circumstance. A seed phrase typed into anything other than the wallet’s own screen during a legitimate recovery is a seed phrase that now belongs to someone else. Trezor’s underlying hardware was not compromised in this incident; the entire attack lived in the inbox, not on the device.
Scope: who got emailed, who clicked
Trezor’s disclosure splits the incident into two numbers that matter for different reasons. The company said, in comments reported by BleepingComputer: “The incident affected our opt-in newsletter database, roughly 347,000 email addresses.” That’s the exposure number, everyone who was sent the phishing message. Separately, BleepingComputer reported that around 2,500 users clicked the embedded malicious link before Trezor disabled the phishing domain, a window the company has described as lasting about 20 minutes from discovery to takedown.
That’s a click-through rate near 0.7%, which sounds small until you remember the denominator is a third of a million people who explicitly opted in to hear from a hardware wallet company, a population that skews toward people who already hold crypto worth stealing. Not every click equals a drained wallet; clicking a link is not the same as typing a seed phrase into a fake app. But it’s the pool of accounts now facing the highest risk, and the one Trezor is watching most closely for fraud reports in the coming weeks.
Trezor’s rough 2026: a pattern, not a one-off
This is not Trezor’s first vendor-side security headache this year. In August 2026, the company disclosed a separate breach tied to ShipMonk, its shipping and logistics provider, that initially affected close to 14,000 customers whose order data, names, emails, phone numbers, and shipping addresses, was exposed. BleepingComputer later reported that the scope of that breach grew to 81,000 affected customers as the investigation continued, with Trezor specifying 11,742 customers fully exposed and 1,947 partially exposed within that total.
Put the two incidents side by side and a pattern emerges: Trezor’s core hardware and firmware haven’t been the entry point, its vendors have. A shipping partner leaked customer addresses. A marketing platform leaked customer inboxes. Both incidents ultimately funneled into the same outcome, phishing attempts against crypto holders, just via different data sets. For a company whose entire pitch is that your keys never leave the device, the optics of two vendor breaches inside two months are rough regardless of where the technical fault sits.
Why crypto holders are a uniquely attractive phishing target
Phishing campaigns against bank customers are common and mostly reversible: banks can freeze accounts, claw back wire transfers, and issue chargebacks. Crypto transactions clear in minutes and don’t reverse. Once a seed phrase is typed into a phishing app, funds can move to an attacker’s wallet and be laundered through mixers or cross-chain bridges before the victim even notices the balance is gone. That asymmetry, instant finality with no recall button, is why hardware wallet customers specifically get targeted with this much effort: the payout per successful phish tends to be dramatically higher than a stolen credit card number.
It also explains why attackers invest in details like using a real sender domain and referencing an actual chip family. Generic “your account is locked” phishing gets caught by spam filters and user instinct. A technically specific alert, sent from a domain the recipient already trusts, is built to survive both.
How this compares to other hardware wallet vendor breaches
Trezor isn’t the only wallet maker whose customers have been hit by vendor-side breaches this year. BitBox users were also targeted in the same newsletter phishing spree, according to The Register’s reporting, suggesting the Brevo-linked incident touched more than one hardware wallet brand simultaneously. That detail matters: it points to a breach at the marketing-platform layer rather than anything unique to Trezor’s own security posture, though it doesn’t make the impact on Trezor’s customer base any smaller.
| Metric | Trezor / Brevo phishing (Sept. 2026) | Trezor / ShipMonk breach (Aug. 2026) |
|---|---|---|
| Breached party | Third-party email provider (Brevo, per multiple outlet reports) | ShipMonk, shipping/logistics provider |
| Data exposed | Newsletter email addresses used to send phishing emails | Names, emails, phone numbers, shipping addresses |
| People affected | ~347,000 emails targeted | ~81,000 customers (grew from an initial ~14,000) |
| Confirmed victims | ~2,500 users clicked the malicious link | 11,742 fully exposed; 1,947 partially exposed |
| Attack vector | Phishing email from spoofed-legitimate domain | Downstream phishing/fraud risk from leaked contact data |
| Trezor device/firmware compromised? | No | No |
The technical lure: why STM32 was chosen
STM32 microcontrollers, made by STMicroelectronics, are widely used across the hardware security industry, not exclusive to Trezor, which is exactly why referencing them worked as a scare tactic. An “entropy vulnerability” framing plays on a real cryptographic concern: if a device’s random number generator produces predictable output, keys derived from it can, in theory, be guessed faster than brute force should allow. Real entropy flaws have happened in embedded hardware before, which gave the fake alert just enough plausibility to get read past the subject line. There is no confirmed STM32 entropy defect tied to Trezor devices; the vulnerability described in the phishing email was fabricated as bait, not a real disclosed flaw.
What security researchers and the company are saying
Trezor’s own communications have been the primary on-record source throughout this incident, and the company has been direct about both the cause and the response. As quoted by BleepingComputer, Trezor said: “On September 9, 2026, Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts.” On the scale of exposure, the company added: “The incident affected our opt-in newsletter database, roughly 347,000 email addresses.” And on containment: “No other Trezor system was touched. We have suspended the Brevo account to stop further email distribution.” Each of these statements traces back to BleepingComputer’s reporting and Trezor’s own public statement on X.
Market and industry impact
Hardware wallet makers sell trust as much as they sell devices, and repeated vendor breaches chip away at that pitch even when the core product holds up. Trezor’s stock-in-trade promise, that private keys never touch an internet-connected system, remains technically true here: nothing about this incident implicates the Trezor device’s firmware or secure element. But customers weighing a hardware wallet purchase don’t always parse that distinction, and two vendor-side incidents in two months give competitors an opening to point at Trezor’s broader security operations rather than just its hardware.
The wider effect lands on the vendor ecosystem itself. Email marketing platforms like Brevo sit downstream of thousands of businesses, and a single breach there can ripple out to any brand using the service, crypto-related or not. Expect scrutiny on third-party email vendors serving financial and crypto brands to increase, with procurement teams asking harder questions about SOC 2 status, access controls, and incident history before signing contracts.
Historical context: phishing has always followed the money in crypto
Crypto phishing campaigns tend to spike whenever attackers find a new trusted channel to abuse. Fake wallet-connect prompts, cloned exchange login pages, and Discord bot compromises have each had their moment as the go-to delivery method. Vendor-email compromise, using a real company’s own newsletter infrastructure, is a newer variant that has gained traction over the last two years precisely because so many companies outsource marketing email to third parties without treating that vendor relationship as a security dependency. Trezor’s incident sits in that lineage: the attackers didn’t need to breach Trezor at all, they needed to breach one company Trezor trusted with a mailing list.
Practical steps for Trezor customers right now
Anyone who received the “Critical Security Alert: STM32 Entropy Vulnerability” email, or any similar unsolicited security alert claiming to be from Trezor, should treat it as malicious by default. The core rule doesn’t change: a seed phrase never gets typed into a website, an app, or an email form, full stop. If you clicked the link but did not enter your recovery phrase or connect a wallet, your funds are very likely still safe; if you entered any part of your seed phrase anywhere outside your physical Trezor device, move funds to a new wallet with a freshly generated seed immediately.
| Action | Why it matters | Priority |
|---|---|---|
| Never enter a seed phrase into any app, site, or email form | Legitimate wallets only accept seed input on the physical device screen | Critical |
| Verify sender domain and links before clicking | This attack used a real Trezor sending domain, so domain checks alone weren’t enough | High |
| Move funds to a new wallet if a seed phrase was ever exposed | An exposed seed phrase should be treated as permanently compromised | Critical |
| Enable a passphrase (25th word) on hardware wallets that support it | Adds a second secret an attacker would also need to steal funds | Medium |
| Unsubscribe from or filter marketing newsletters tied to financial accounts | Reduces exposure to future vendor-side email breaches | Medium |
| Report phishing domains to the wallet vendor and registrar | Speeds up takedown for other targeted users | Low |
What Trezor still hasn’t answered
Several details remain open as of this writing. Trezor has not published a full post-incident report detailing exactly how the attackers gained access to send mail through its Brevo account, whether that access came via stolen credentials, an API key leak, or a broader Brevo-side compromise touching the other 120-plus affected accounts. It’s also unclear whether Trezor plans to keep using Brevo going forward or migrate its newsletter infrastructure to a different provider. Until Trezor or Brevo publish more, the exact root cause should be treated as unconfirmed.
Predictions: where this goes from here
- Expect Trezor to publish a more detailed post-mortem within the next few weeks, likely including whether Brevo access came from a stolen API key or credential set, given the pressure from customers and press coverage.
- Other Brevo customers beyond Trezor and BitBox will likely disclose similar phishing incidents in the coming days, since BleepingComputer’s reporting already puts the number of affected Brevo accounts above 100.
- Hardware wallet vendors across the industry will accelerate efforts to bring newsletter and customer-communication infrastructure in-house, or at minimum add stricter monitoring on outbound vendor email, to avoid repeating this exact attack path.
- Expect a wave of copycat phishing emails referencing “entropy vulnerabilities” or similar technical-sounding hardware flaws across other crypto hardware brands, since the lure’s plausibility is what made it effective, not anything unique to Trezor’s wording.
- Regulatory and industry pressure on email marketing vendors serving financial and crypto clients will increase, with more companies requiring proof of stronger access controls before signing new contracts.
The bigger lesson: your security is only as strong as your weakest vendor
Trezor’s device-level security isn’t what failed here, and that distinction matters. But it’s also increasingly irrelevant to the average customer’s risk exposure, because the attack surface for any company today includes every vendor that touches customer data, not just the core product. A marketing email platform, a shipping partner, a support ticketing tool, any of these can become the entry point for an attack against a company’s most security-conscious customers. For an industry built on the promise of eliminating trusted third parties, that’s an uncomfortable irony worth sitting with.
Frequently asked questions
Is my Trezor hardware wallet itself compromised?
No. Nothing in this incident indicates that Trezor’s device firmware, secure element, or key generation was compromised. The breach affected a third-party email provider used for newsletters, not the hardware wallet itself.
What was the fake email actually called?
The phishing email used the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and was sent from [email protected], Trezor’s legitimate support address, because it went out through the compromised third-party email system rather than a spoofed address.
How many people were affected?
Trezor said roughly 347,000 newsletter email addresses were targeted. Separately, BleepingComputer reported that around 2,500 users clicked the malicious link before the phishing domain was taken down.
Was the email provider named Brevo?
Multiple outlets, including The Register and KuCoin’s news desk, have reported that the breached provider was Brevo, the marketing platform Trezor uses for its newsletter. Trezor’s own statement, as quoted by BleepingComputer, referenced a Brevo security incident affecting 120 Brevo accounts.
What should I do if I clicked the phishing link?
If you clicked the link but never entered any part of your recovery seed phrase, your funds are very likely unaffected. If you entered any portion of your seed phrase into the linked app or site, treat that wallet as compromised and move your funds to a newly generated wallet immediately.
Is this related to Trezor’s ShipMonk breach from August 2026?
They are separate incidents involving different vendors. The ShipMonk breach exposed shipping and contact data for tens of thousands of customers, while this incident involves a different vendor, Brevo, and different data, newsletter email addresses used to send phishing messages.
Were other hardware wallet brands affected?
Yes. The Register reported that BitBox users were also targeted in the same newsletter phishing campaign, suggesting the underlying vendor breach extended beyond Trezor’s account alone.
Does a hardware wallet ever need my seed phrase over email or in an app?
No, never. Legitimate wallet recovery only happens by entering a seed phrase directly on the physical device’s screen. Any email, app, or website asking for a seed phrase is a phishing attempt, regardless of how convincing the sender address looks.




