14 days ago
TechCrunch Sep 11, 2026

Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

Hardware crypto wallet company Trezor has warned its customers about a recent data breach involving Brevo, its third-party email provider. This cyberattack allowed hackers to send approximately 347,000 phishing emails to Trezor users, containing malicious links that, if clicked, download an app designed to steal wallet backup passwords. One of the subject lines used in these phishing attempts was “Critical Security Alert: STM32 Entropy Vulnerability,” aiming to create a sense of urgency around security.

Brevo reported that hackers accessed 138 of its accounts, exploiting a flaw that gave them broader access than intended across multiple organizations, including Trezor. The compromised access enabled the attackers to reach a large volume of Trezor customers with phishing messages. While Trezor emphasized that its products, wallets, and account systems were not directly affected in this breach, the incident highlights the vulnerabilities that come from reliance on third-party providers for critical communications.

This breach follows another recent security incident that impacted Trezor customers. In August, Trezor revealed that a data breach at ShipMonk, its shipping partner, exposed personal details such as names, addresses, emails, and phone numbers for at least 81,000 customers who purchased hardware wallets. This previous leak has already led to targeted scam attempts, including fraudulent mail featuring QR codes that direct victims to fake sites attempting to steal wallet passwords.

In reaction to these breaches, Trezor is reassessing its vendor partnerships and has cautioned users that their emails might continue to be targeted in future phishing attacks. The company continues to advise vigilance among its community to avoid falling victim to scams that exploit compromised customer data, underscoring the risks crypto owners face from third-party data compromises even when their wallets themselves remain secure.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.