Particle.news
Download on the App Store

Phishing Campaign Sent From Trezor’s Legitimate Domain After Brevo Login Flaw Hits 347,000 Subscribers

The breach shows how a third‑party email provider’s access control failure can let attackers send credible security alerts that trick large numbers of hardware‑wallet users.

Overview

  • Trezor said Wednesday that an attacker abused a flaw in marketing platform Brevo to send a fake “Critical Security Alert: STM32 Entropy Vulnerability” email to about 347,000 newsletter subscribers and that the company disabled the malicious domain and suspended its Brevo account.
  • Trezor reported roughly 2,500 people clicked the malicious link before the domain was taken down within about 20 minutes, and the company says no passwords or wallet data were stored in its Brevo account.
  • Security reporting and Brevo disclosures describe an authorization/login boundary failure that let the attacker access 138 client accounts and send messages from legitimate provider infrastructure so the emails bypassed usual spoofing checks.
  • The phishing push follows an August ShipMonk logistics breach that exposed roughly 81,000 Trezor customer contact records, a combination security teams warn could make future impersonation and targeted scams more convincing.
  • Trezor, BitBox and CoinTracking are investigating, advising users never to enter recovery seeds or follow unexpected security links, and industry observers say the incident should force stricter vendor vetting and tighter access controls for wallet companies.