Trezor said attackers breached its third-party email provider (Brevo) and gained access to Trezor’s email domain, triggering phishing emails to subscribers. The scam emails used a fake “critical security alert” about a supposed microcontroller vulnerability and attempted to trick users into handing over their wallet backups.
Key findings
- Trezor reported its third-party email provider Brevo was breached and that attackers accessed Trezor’s email domain.
- Users received phishing emails with the subject “Critical Security Alert: STM32 Entropy Vulnerability.”
- The phishing attempt tried to convince users to “give up their wallet backups.”
- Other crypto firms using Brevo (BitBox, CoinTracking, Peach Bitcoin, Blocktrainer) warned users about phishing attempts tied to similar fake breach/vulnerability claims.
Who’s being targeted
- Commonly targeted roles: All staff (general phishing awareness), Customer Support, Marketing/CRM teams, Security/IT incident response, Executives (brand impersonation and customer communications approval).
- Affected industries: Cryptocurrency / digital assets, Financial services, Technology vendors serving crypto firms.
- Attack channels: email.
- Impersonated: Trezor (newsletter/security team), CoinTracking (security/breach notification).
Awareness takeaways
- Treat unexpected ‘critical security’ emails as suspicious, verify via official channels before clicking anything.
- Never share wallet backups/seed phrases; any request for them is a major red flag.
- Third-party provider breaches can be used to make phishing emails look legitimate, so increase scrutiny after vendor incidents.
Red flags to watch for
- Urgent ‘critical security alert’ tone pushing immediate action
- Request to provide wallet backups/seed phrase (a high-risk request)
- Trezor warned the message is not from them and told users not to click links
- Breach claim may be fabricated to drive panic
- Security messages arriving unexpectedly via email
- Multiple firms warning about phishing related to the same email provider incident
Read the video transcript
You get an email from Trezor: subject line screams, “Critical Security Alert: STM32 Entropy Vulnerability.” Looks legit, right? Behind the scenes, Trezor’s email provider, Brevo, was breached. Scammers used Trezor’s real email domain to blast this fake alert and push you to “secure” your wallet by giving up your backup. Here’s the tell: no legitimate crypto service, Trezor, BitBox, CoinTracking, anyone, will ever ask for your wallet backup or seed phrase by email. The moment you see that request, it’s game over for the scammer if you stop. So if you get any “critical security alert” email, don’t click, go to the service’s website or app yourself and check there instead.