Trezor says a breach at its third-party email provider let attackers send a phishing message through infrastructure tied to Trezor’s legitimate domain, creating the kind of attack that can defeat one of users’ most basic scam checks: looking at who sent the email.
According to Trezor’s incident report, unauthorized access at email provider Brevo affected the company’s newsletter environment. Trezor later said 347,149 marketing email contacts were exported through the provider’s API, while its hardware wallets, wallet software and private-key systems remained unaffected.
The malicious message warned recipients about a fabricated “STM32 Entropy Vulnerability” and pushed them toward a download that ultimately sought wallet backup information. Trezor says it disabled the affected email path and took down the malicious domain route quickly after detecting the campaign.
A real sender domain made the phishing harder to spot
BleepingComputer independently reported that customers received the fake security warning from infrastructure associated with Trezor’s legitimate email domain. That is materially different from the familiar phishing pattern in which a scammer registers a misspelled lookalike domain and hopes the recipient fails to notice.
Trezor publicly warned customers in an official X security alert, telling users that its third-party email provider had been breached and that the “Critical Security Alert: STM32 Entropy Vulnerability” message was phishing.
The weak point was outside the wallet
The incident is a reminder that a secure device can sit inside a much larger trust chain. A hardware wallet may protect signing keys correctly while an email provider, fulfillment service, support platform or customer database still gives attackers a route to the human holding the device.
BitcoinVersus.Tech recently covered the investigation into a suspected ShinyHunters member reportedly assisting the FBI, another example of how modern attacks often target identity, access and third-party systems rather than trying to defeat cryptography directly.
The same distinction matters in exchange security. In our coverage of funds moving after the Bitget security incident, the operational question extended beyond individual wallet keys to backend controls, authorization systems and how compromised access can propagate through infrastructure.
Sender verification alone is no longer enough
For users, the lesson is uncomfortable but useful: an email coming from an expected domain is evidence, not proof. High-confidence wallet security still depends on refusing to type a recovery phrase into a website or downloaded application, verifying urgent claims through a separate trusted channel and treating unsolicited firmware or security instructions as hostile until independently confirmed.
That layered approach is consistent with BitcoinVersus.Tech’s broader seven-layer cybersecurity framework: endpoint security is only one layer, and attackers can move to identity, communication or supply-chain systems when the core device is harder to compromise.
Trezor says no wallet backup data was stored by Brevo and that its products themselves were not compromised. The exposure still matters because a stolen marketing list can make future phishing attempts more targeted, while the use of trusted-looking email infrastructure can make those attempts more convincing.
The strongest part of a hardware wallet may be the chip holding the keys. The weakest part can still be the message that convinces a person to hand those keys away.
BitcoinVersus.Tech
Advertisement
BitcoinVersus.Tech Editor’s Note:
We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support to help further secure the integrity of our research initiatives, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb
BitcoinVersus.tech is not a financial advisor. This media platform reports on financial subjects purely for informational purposes.

Leave a comment