< Back to all clusters
[TECHNOLOGY] · United States, France, Germany, Japan, Brazil · 18 sources

started · updated

Trezor warns of phishing campaign following Brevo email provider breach

Hardware wallet manufacturer Trezor has warned users of a sophisticated phishing campaign following a security breach at its third-party email service provider, Brevo. The attackers exploited a flaw in Brevo’s login and authorization systems, specifically involving single sign-on (SSO) configurations, to gain access to multiple client accounts.

Using these compromised accounts, hackers sent fraudulent emails from Trezor’s legitimate domain. The messages, titled ‘Critical Security Alert: STM32 Entropy Vulnerability’, falsely claimed that a hardware-level defect in STM32 microcontrollers could compromise recovery phrases. The emails aimed to trick users into visiting a malicious site to download an application and reveal their wallet seed phrases.

Approximately 347,000 Trezor newsletter subscribers were targeted, with an estimated 2,500 users clicking the malicious link before Trezor could disable the fraudulent domain. Other cryptocurrency-related firms using Brevo, including BitBox and CoinTracking, also reported phishing attempts or unauthorized activity.

Trezor emphasized that its actual hardware devices, software, and private keys remain secure, as the breach was limited to external communication infrastructure. The company is currently investigating the incident and reviewing its third-party vendor security requirements.

Entities

BitBox · Brevo · Casa · CoinTracking · Nick Neuman · STM32 · Trezor

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

2 days ago
about 12 hours ago
about 3 hours ago