Marcus Chen
September 11, 2026
13 min read
Trezor, the crypto hardware wallet maker owned by SatoshiLabs, confirmed on September 11, 2026 that attackers breached its third-party email marketing provider, Brevo, and used that access to blast phishing emails to roughly 347,000 addresses pulled from its opt-in newsletter database. The company says about 2,500 people clicked the malicious link before it disabled the phishing domain, and it stresses that no wallet seeds, PINs, or device firmware were touched directly. The story was first reported by BleepingComputer on September 9-10 and confirmed with fuller numbers by TechCrunch and SecurityWeek on September 11.
The incident matters beyond Trezor’s user base because it shows, again, that the weakest link in hardware wallet security isn’t the chip inside the device. It’s the marketing stack, the shipping vendor, the support ticketing system, and every other third-party contractor that touches a customer’s email address. Trezor customers weren’t hacked because their seed phrase was cracked. They were targeted because a vendor two steps removed from the wallet itself got popped, and the resulting email looked, smelled, and authenticated like it came straight from Trezor.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What happened: the Brevo breach and the phishing wave
On September 9, 2026, phishing emails went out to Trezor newsletter subscribers with the subject line “Critical Security Alert: STM32 Entropy Vulnerability.” The message claimed a hardware flaw in the STM32 microcontrollers used inside Trezor devices could let attackers brute-force user seeds, and it pushed recipients to click a link to “check” whether their device was affected, according to reporting from BleepingComputer and SecurityWeek.
The trick worked because the email wasn’t spoofed in the traditional sense. It went out through Trezor’s own Brevo-hosted newsletter infrastructure, meaning it passed SPF, DKIM, and DMARC checks and could legitimately appear to come from an address like [email protected]. The link inside pointed to a tracking subdomain resembling Trezor’s own mailing infrastructure, which made it look clean even to attentive users. Anyone who clicked through was pushed toward downloading an app and entering their wallet backup phrase, the exact action Trezor tells every customer never to take.
Trezor moved fast once it noticed the traffic. The company posted on X the same day: “Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.” (source). The company says it disabled the malicious domain within roughly 20 minutes of the campaign starting, which limited how many people could reach the credential-harvesting page.
Brevo, the email marketing platform, separately confirmed that attackers had broken into somewhere between 120 and 138 customer accounts on its platform and used that access to send mass phishing emails to multiple companies’ contact lists, not just Trezor’s. Brevo said it shut down the unauthorized access at 09:30 UTC on September 10. Trezor responded by suspending its own Brevo account entirely to stop any further distribution while it investigated how the access happened in the first place.
The scale: 347,000 targeted, 2,500 clicked
Trezor has been explicit that the 347,000 addresses now carry ongoing risk. In its statement, the company warned that the exposed list “might be potentially used for other phishing attacks in the future,” meaning this isn’t a one-and-done event. Anyone on that newsletter list should expect copycat phishing waves for months, not days, since the email addresses themselves are now circulating in whatever channels the original attackers use to monetize stolen contact data.
Adding to the pressure on Trezor customers this week, the company separately disclosed a breach at ShipMonk, one of its logistics and order-fulfillment vendors, exposing roughly 80,689 customer records including names, email addresses, phone numbers, and shipping addresses, according to a Trezor blog post. The two incidents are unrelated in cause but compound the same problem: attackers now have layered, cross-referenced data (shipping addresses plus newsletter emails) that makes future social-engineering attempts far more convincing than a generic phishing blast.
Why this phishing email was so effective
Security researchers who reviewed the campaign flagged several design choices that made it more convincing than a typical crypto scam email. First, it used a plausible technical hook: STM32 microcontrollers are real components used in various embedded and hardware wallet products, so referencing an “entropy vulnerability” sounded specific rather than generic. Second, the sender infrastructure was legitimate, since the email actually originated from Trezor’s own vendor-hosted mailing system rather than a spoofed lookalike domain. Third, the urgency framing, a security alert demanding immediate action, is a well-tested social engineering pattern that short-circuits careful reading.
Trezor’s own long-standing guidance anticipates exactly this kind of attack. The company’s security documentation states plainly: “The rule is simple: any request for your wallet backup, PIN, passwords, or codes is always a scam” (ut the September 9 campaign is a real-world test of whether users actually internalize it when the request arrives from what looks like an authentic company channel
Trezor’s official response
Trezor’s public communication followed a fairly standard incident-response arc: acknowledge fast, contain the immediate threat, then disclose scope once the investigation had numbers to share. The initial X post on September 9 focused entirely on stopping the bleeding, telling users not to click any links and confirming the company had already taken the malicious domain down. Two days later, the company’s fuller statement narrowed the blame to Brevo specifically, writing that the incident “affected our opt-in newsletter database, roughly 347,000 email addresses” and that “no other Trezor system was touched.”
That distinction, no other Trezor system touched, is the throughline of the company’s messaging this week. Trezor wants customers to understand that wallet firmware, the Trezor Suite application, and the cryptographic operations on the physical device were never in the attackers’ reach. The exposure is confined to marketing and shipping vendors sitting outside the core security perimeter. Whether that distinction lands with a nervous crypto-holding public is a separate question, since a breach headline reading “Trezor” tends to travel faster than the nuance of which specific system was affected.
Historical context: hardware wallets keep losing the vendor fight
This is not the crypto hardware wallet industry’s first vendor-side data exposure, and it won’t be the last. Ledger, Trezor’s closest rival, suffered a widely reported e-commerce and marketing database breach in 2020 that exposed customer names, addresses, and phone numbers, fueling years of targeted phishing and even physical threats against known Ledger owners. The pattern that emerged then, attackers using leaked shipping or contact data to build highly targeted, device-specific phishing, is functionally identical to what’s playing out with Trezor and Brevo now. The lesson the industry drew from Ledger’s 2020 breach was supposed to be that customer contact data deserves the same security rigor as the wallets themselves. Six years later, the same failure mode is repeating with a different vendor name attached.
What’s changed since 2020 is the sophistication of the follow-on attack. Where earlier hardware wallet phishing campaigns relied on crude spoofed domains and obvious grammar mistakes, the September 2026 Trezor campaign exploited legitimate infrastructure end to end. The email authenticated cleanly, the tracking subdomain resembled Trezor’s real mailing system, and the technical pretext (a chip-level entropy flaw) was specific enough to sound credible to a security-conscious audience that would normally distrust a generic “your wallet is at risk” message.
Competitive landscape: how hardware wallet vendors compare on vendor risk
The incident puts a spotlight on how differently major hardware wallet makers handle third-party vendor exposure, and how quickly they disclose when something goes wrong.
| Vendor | Reported incident | Scope disclosed | Public disclosure speed |
|---|---|---|---|
| Trezor (SatoshiLabs) | Brevo email provider breach, Sept 2026 | ~347,000 newsletter addresses; ~2,500 clicks | Same-day public warning via X, full scope within 48 hours |
| Trezor (SatoshiLabs) | ShipMonk shipping vendor breach, Sept 2026 | ~80,689 customer shipping/order records | Disclosed via company blog within the same week |
| Ledger | E-commerce/marketing database breach, 2020 | Customer names, emails, physical addresses (widely reported at the time) | Disclosed weeks after initial detection, per contemporaneous reporting |
| BitBox (Shift Crypto) | Phishing campaign referencing compromised email infrastructure, Sept 2026 | Not fully quantified in current reporting | Flagged alongside the Trezor/Brevo campaign by security researchers |
Trezor’s response this week compares favorably on speed, a same-day public warning is meaningfully faster than the multi-week gaps that characterized some earlier industry breaches. Where the comparison gets less favorable is scope: two separate vendor-side incidents disclosed in the same week (Brevo and ShipMonk) suggest Trezor’s third-party vendor security review process has structural gaps that a single fast X post doesn’t fix.
Market and industry impact
Hardware wallets exist specifically to remove the single biggest attack surface in crypto custody: internet-connected key storage. A breach that undermines confidence in the ecosystem around the wallet, even without touching the wallet itself, chips away at the core value proposition these companies sell. Every hardware wallet maker’s pitch rests on the idea that keeping keys offline makes users safe from exactly this kind of remote compromise. When a sophisticated, well-targeted phishing campaign can still route around that protection by exploiting a marketing vendor, it reopens the debate over whether “cold storage” claims oversell the actual security boundary.
There’s also a knock-on effect for the broader email marketing supply chain that crypto and fintech companies rely on. Brevo (formerly known as Sendinblue) serves a large base of small and mid-size businesses, and this incident, alongside the fact that Brevo’s compromised accounts reportedly touched a customer list broader than Trezor alone, raises the question of how many other companies in adjacent industries are sitting on similarly exposed contact databases without realizing it yet.
What crypto users should do right now
Trezor’s guidance, echoed consistently across its public statements and long-standing security documentation, comes down to a short list of concrete actions.
- Delete, don’t click, any email referencing “Critical Security Alert: STM32 Entropy Vulnerability,” even if the sender address looks legitimate.
- Never enter a wallet backup phrase, PIN, or recovery seed into any website, app, or browser form. It only belongs on the physical hardware device itself.
- Type Trezor’s official domain directly into the browser rather than clicking any link from an email, no matter how urgent the subject line sounds.
- Assume any address on Trezor’s newsletter list may see follow-on phishing attempts for months, and treat unsolicited “security alert” emails with extra suspicion going forward.
- If you clicked the link and entered any wallet information, move funds to a new wallet with a freshly generated seed immediately, and treat the old device or seed as compromised.
- Watch account activity for unusual transactions, and report suspected phishing directly to Trezor’s support channels rather than replying to the suspicious email.
Expert and company statements
Trezor’s public messaging has been unusually direct compared to typical corporate breach language. In its initial warning, the company wrote: “Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.” (Trezor, official company account
The company’s incident summary was similarly blunt about the” it stated in the same public post (Trezor
Trezor’s longer-standing security guidance, published before this incident but directly relevant to it, sets the baseline every customer is expected to follow: “The rule is simple: any request for your wallet backup, PIN, passwords, or codes is always a scam” (Trezor, official security guidance, source). The company reinforces that point with an unambiguous instruction to users: “Remember, NEVER share your wallet backup — it must always stay private and offline. Trezor will never ask for your wallet backup.” This same warning was cited in earlier phishing-related coverage of Trezor’s support channels, underscoring that the underlying advice hasn’t changed even as the delivery mechanism for attacks keeps evolving.
Timeline of the Trezor-Brevo incident
| Date | Event |
|---|---|
| Before Sept 9, 2026 | Attackers gain unauthorized access to 120-138 Brevo customer accounts, including Trezor’s |
| Sept 9, 2026 | Phishing emails sent to ~347,000 Trezor newsletter addresses; Trezor disables the malicious domain within ~20 minutes and posts a public warning on X |
| Sept 10, 2026 (09:30 UTC) | Brevo confirms it closed the unauthorized account access and publishes an incident status update |
| Sept 10-11, 2026 | Security outlets and threat trackers report on the campaign; Trezor separately discloses the ShipMonk shipping-vendor breach (~80,689 records) |
| Sept 11, 2026 | Trezor publishes full scope: ~347,000 addresses targeted, ~2,500 clicks; TechCrunch and SecurityWeek publish detailed coverage naming Brevo |
Predictions: what happens next
- Expect at least one more wave of copycat phishing targeting the same 347,000 addresses within the next 60-90 days, since the exposed list itself has ongoing resale and reuse value to scammers.
- Brevo will likely face scrutiny from other client companies beyond Trezor, given that its compromised accounts reportedly extended past a single customer’s contact list, and expect additional named victims to surface in security reporting over the coming weeks.
- Hardware wallet makers, including Trezor’s direct competitors, will probably accelerate messaging around “your seed only goes on the device,” using this incident as a teaching moment even for their own customer bases.
- Regulatory and consumer-protection attention on crypto-adjacent vendor risk is likely to grow, following the same trajectory seen after Ledger’s 2020 breach, where third-party data exposure became a recurring talking point in crypto security audits.
- Trezor will likely face pressure to publish a more detailed post-incident report covering how Brevo access was obtained and what vendor security requirements the company plans to change, similar to how other breached companies have handled post-mortem disclosure.
How this compares to typical crypto phishing campaigns
Most crypto phishing relies on spoofed domains, close but not exact lookalike URLs, or fake browser extensions. Those attacks depend on the victim not noticing a slightly wrong domain name or an unfamiliar sender address. The Trezor-Brevo campaign skipped that weak link entirely by using real, authenticated infrastructure. That’s a meaningfully harder attack for the average user to catch, since the usual advice, check the sender address, hover over the link, look for domain typos, doesn’t work when the infrastructure itself is legitimate but compromised upstream.
This shifts the practical defense away from email literacy and toward a much simpler, harder rule: no website, app, or email ever needs your wallet backup phrase, full stop, regardless of how legitimate the request looks or where it appears to come from. That single behavioral rule would have stopped every one of the roughly 2,500 people who clicked through this specific campaign, provided they held the line at the final step.
The Brevo side of the story
Brevo’s own account of the incident, an unauthorized party gaining access to somewhere between 120 and 138 customer accounts on its platform, points to a credential-based intrusion rather than a platform-wide software vulnerability, based on available reporting. That distinction matters for other Brevo customers: if the access came through compromised individual account credentials rather than a flaw in Brevo’s core systems, the fix on Brevo’s end is different (forcing password resets, enabling stronger authentication) than it would be for a codebase-level vulnerability. Brevo has not, as of this reporting, published a full technical post-mortem explaining exactly how the 120-138 accounts were accessed.
Data table: reported figures at a glance
| Metric | Figure | Source |
|---|---|---|
| Newsletter addresses targeted | ~347,000 | Trezor statement, via BleepingComputer/SecurityWeek |
| Users who clicked the malicious link | ~2,500 | Trezor statement |
| Brevo accounts accessed by attackers | 120-138 (reports vary) | Brevo incident update, via TechCrunch |
| Time to disable phishing domain | ~20 minutes | Trezor statement |
| ShipMonk records exposed (separate incident) | ~80,689 | Trezor blog post |
| Brevo access shutdown time | 09:30 UTC, Sept 10, 2026 | Brevo status update, via reporting |
Why hardware wallets remain the safer choice despite this
None of this changes the fundamental security math around hardware wallets. The device itself was never in the attackers’ reach, and the entire campaign depended on tricking a user into voluntarily typing their seed phrase somewhere it never belongs. That’s a social engineering failure, not a cryptographic one. Software wallets and exchange-held funds remain exposed to a far broader set of remote attack vectors that don’t require any user mistake at all. The takeaway isn’t that hardware wallets failed; it’s that the vendor ecosystem surrounding them needs the same security discipline as the wallets themselves.
Still, the incident is a reminder that “cold storage” only protects the parts of the system that are actually cold. Email newsletters, shipping labels, support tickets, and marketing databases are all warm, internet-connected, and, as this week demonstrated twice over for Trezor alone, frequently the actual point of failure.
Frequently asked questions
Was my Trezor wallet hacked directly?
No. Trezor says the breach was confined to its third-party email provider, Brevo, and its shipping vendor, ShipMonk. The wallet firmware, Trezor Suite software, and on-device cryptographic operations were not affected according to the company’s statements.
How do I know if my email was among the 347,000 targeted?
If you’re subscribed to Trezor’s newsletter and received an email titled “Critical Security Alert: STM32 Entropy Vulnerability” around September 9, 2026, your address was part of the targeted list. Trezor has not published a public lookup tool to individually check inclusion.
I clicked the link. What should I do now?
If you entered your wallet backup phrase or downloaded any app prompted by the email, treat your seed as compromised. Move any funds to a new wallet with a freshly generated seed as soon as possible, and monitor your accounts for suspicious transactions.
Is the STM32 entropy vulnerability described in the email real?
No. Trezor has confirmed the email is a phishing attempt and the claimed vulnerability is not a legitimate security advisory from the company.
What is Brevo, and why did Trezor use it?
Brevo (formerly Sendinblue) is a third-party email marketing platform that many companies, including Trezor, use to send newsletters and customer communications. Trezor used it for newsletter distribution, not for core wallet operations.
Did other hardware wallet companies get affected?
Reports indicate a phishing campaign referencing compromised email infrastructure also targeted BitBox users around the same period, though the full scope for BitBox has not been quantified in current reporting.
Will Trezor compensate affected users?
Current reporting does not indicate any compensation program. Trezor’s public response has focused on containment, disclosure, and user guidance rather than financial remediation.
How can I verify a security email is actually from Trezor?
Trezor recommends never clicking links in unsolicited security emails. Instead, navigate directly to Trezor’s official website by typing the address yourself, and check the company’s verified social media accounts for confirmed announcements before taking any action.
