started · updated
Trezor warns of phishing campaign following Brevo email provider breach
Hardware wallet manufacturer Trezor has warned users of a sophisticated phishing campaign following a security breach at its third-party email service provider, Brevo. The attackers exploited a flaw in Brevo’s login and authorization systems, specifically involving single sign-on (SSO) configurations, to gain access to multiple client accounts.
Using these compromised accounts, hackers sent fraudulent emails from Trezor’s legitimate domain. The messages, titled ‘Critical Security Alert: STM32 Entropy Vulnerability’, falsely claimed that a hardware-level defect in STM32 microcontrollers could compromise recovery phrases. The emails aimed to trick users into visiting a malicious site to download an application and reveal their wallet seed phrases.
Approximately 347,000 Trezor newsletter subscribers were targeted, with an estimated 2,500 users clicking the malicious link before Trezor could disable the fraudulent domain. Other cryptocurrency-related firms using Brevo, including BitBox and CoinTracking, also reported phishing attempts or unauthorized activity.
Trezor emphasized that its actual hardware devices, software, and private keys remain secure, as the breach was limited to external communication infrastructure. The company is currently investigating the incident and reviewing its third-party vendor security requirements.
Entities
BitBox · Brevo · Casa · CoinTracking · Nick Neuman · STM32 · Trezor
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 12 SOURCES] The phishing email used the subject line ‘Critical Security Alert: STM32 Entropy Vulnerability’. bitcoinethereumnews.com · bitnewsbot.com · bitcoinbasis.de · www.criptotendencias.com · mycryptoparadise.com · +6 more
- [● 5 SOURCES] No Trezor devices, software, or private keys were compromised in the breach. bitnewsbot.com · bitcoinethereumnews.com · www.criptotendencias.com · mycryptoparadise.com · www.cryptopolitan.com
- [● 3 SOURCES] Approximately 2,500 users clicked the malicious link before the domain was taken down. bitcoinbasis.de · www.neweconomy.jp · cointelegraph.com
- [● 2 SOURCES] The phishing emails passed standard authentication checks including SPF, DKIM, and DMARC. www.cryptopolitan.com · u.today
- [● 11 SOURCES] Trezor's third-party email provider was breached. bitcoinethereumnews.com · bitnewsbot.com · www.criptotendencias.com · mycryptoparadise.com · www.cryptopolitan.com · +5 more
- [● 3 SOURCES] The attacker exploited a flaw in Brevo's single sign-on (SSO) and authorization boundaries to access multiple client accounts. cryptoast.fr · cointelegraph.com
- [● 4 SOURCES] The email platform Brevo was breached, affecting approximately 347,000 Trezor newsletter subscribers. bitnewsbot.com · www.neweconomy.jp · cointelegraph.com
- [● 5 SOURCES] BitBox users also reported receiving phishing attempts linked to the same provider compromise. bitnewsbot.com · www.spacemoney.com.br · cryptoast.fr · cointelegraph.com