XIYU.NEWS EVENTS

Trezor Warns of Phishing After Email Provider Breach

DevelopingCryptoSecurity incidentFirst tracked 2026-09-10Last changed 2026-09-11

Current outcome

Brevo's postmortem confirms an attacker accessed 138 client accounts through an authorization-boundary flaw in its login system; six were used to send phishing emails and contacts were exported from 43. Trezor's phishing email reached roughly 347,000 subscribers, with about 2,500 people accessing the link before the malicious domain was disabled; Trezor is treating all ~347,000 addresses as known to the attacker and potentially reusable for phishing. Brevo accounts for BitBox and CoinTracking also sent similar fraudulent messages. Trezor maintains that no wallets or private keys were exposed.

Progress timeline

2 material updates
  1. #01
    Initial2026-09-09 23:02 · publication time

    Trezor Warns of Phishing After Email Provider Breach

    Trezor disclosed that its third-party email provider was breached, allowing attackers to send phishing emails from its legitimate domain. The fake alert claims a critical STM32 entropy vulnerability affects some devices and urges users to click a link; Trezor has taken down the malicious domain and is investigating. Because Trezor is a leading hardware wallet maker, a compromised official email channel creates a credible phishing vector that could trick users into exposing recovery phrases or sending funds. The incident, which follows an earlier vendor breach and a recent Coldcard RNG exploit, underscores rising supply-chain and social-engineering risks in the crypto self-custody ecosystem. The phishing email claims engineers found a 'critical hardware-level vulnerability' in STM32 microcontrollers and falsely estimates one in four devices could have weak recovery-phrase randomness. Trezor confirms that no wallets or private keys were exposed, while Casa's Nick Neuman and Jameson Lopp report that BitBox users received similar emails, suggesting the compromise may extend beyond a single provider.

    Source evidence: Decrypt

  2. #02
    Escalation2026-09-11 04:21 · publication time

    Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

    Brevo published a postmortem disclosing the root cause: an attacker created a Brevo account, enabled single sign-on and invited legitimate users into the configuration, causing an authorization boundary failure that granted access to 138 client accounts. Six accounts were used to send phishing emails and contacts were exported from 43 accounts. Trezor confirmed the phishing email went to roughly 347,000 subscribers, that the domain was disabled at the DNS level within 20 minutes, and that about 2,500 people accessed the link before takedown; Brevo accounts belonging to BitBox and CoinTracking were also used for similar phishing emails.

    State after update: Brevo's postmortem confirms an attacker accessed 138 client accounts through an authorization-boundary flaw in its login system; six were used to send phishing emails and contacts were exported from 43. Trezor's phishing email reached roughly 347,000 subscribers, with about 2,500 people accessing the link before the malicious domain was disabled; Trezor is treating all ~347,000 addresses as known to the attacker and potentially reusable for phishing. Brevo accounts for BitBox and CoinTracking also sent similar fraudulent messages. Trezor maintains that no wallets or private keys were exposed.

    Source evidence: Cointelegraph

All events · Back to the feed

XIYU.NEWS APP

Install xiyu.news

Open in a standalone window, check for updates online and read saved pages offline.