Attackers broke into Brevo, the email platform Trezor uses for newsletters, and sent a phishing “security warning” from Trezor’s real mailing system. The email claimed a serious hardware issue could expose wallet recovery seeds and pushed people to a malicious site/app that asked for a wallet backup. The campaign reached 347,000 subscribers, and about 2,500 clicked before Trezor shut it down.
How the Attack Worked
Attackers gained access to Brevo, the third-party email platform Trezor uses to send its newsletters. Using that access, they sent a phishing email directly through Trezor's legitimate mailing system, meaning the message technically came from a real, trusted sending channel. The email warned recipients of a serious 'STM32 Entropy Bug' that could allegedly expose wallet recovery seeds, then directed them to a malicious website and application that asked for their wallet backup. The campaign reached 347,000 subscribers, and roughly 2,500 people clicked the malicious link before Trezor disabled the compromised Brevo account within about 20 minutes and worked to take the malicious domain down at the DNS level.
Why It Succeeded
The core reason this lure worked is that it arrived through a channel recipients already trusted: Trezor's own newsletter system. Most phishing awareness training focuses on spotting spoofed senders or suspicious domains, but this email didn't need to spoof anything, it was sent from the real infrastructure. Combined with a fear-based pretext about a hardware vulnerability threatening users' funds, the message created urgency that pushed people to act before verifying the claim through other means.
What to Watch For
- Requests for a wallet backup or recovery seed, which should never be shared with anyone or entered into an external site
- Urgent claims about device vulnerabilities that pressure immediate action
- Links directing users away from official apps or websites to complete a 'security' step
- Messages that arrive through a normally trusted channel but ask for unusual or sensitive information
Building Resistance
Organizations and individuals should treat messages from trusted brands as one signal of legitimacy, not proof that the instructions inside are safe. Recovery phrases, passwords, and other authentication secrets should be treated as information that is never shared in response to an unsolicited request, regardless of how official the message looks. Because this incident shows how breaching a trusted vendor can give attackers a direct route to a company's audience, IT and security teams managing SaaS or vendor access should plan for the possibility that a legitimate communication platform could be misused to reach users directly. Anyone who did submit a wallet backup on the malicious site should assume compromise and move funds to a new wallet with a new recovery seed immediately.
Key findings
- Attackers used a breach at Brevo (Trezor’s newsletter provider) to send phishing emails through Trezor’s legitimate newsletter channel.
- The lure claimed a serious “STM32 Entropy Bug” could expose wallet recovery seeds, creating urgency and fear.
- Victims were driven to a malicious website/application that requested their wallet backup (recovery seed).
- The campaign hit 347,000 subscribers; 2,500 clicked the malicious link before Trezor intervened.
- Trezor disabled the compromised Brevo account within ~20 minutes and worked to take down the malicious domain at the DNS level.
- Trezor stated its products, infrastructure, and users’ wallets were not compromised, and that clicking alone (without entering wallet backup) was not enough to lose funds.
Who’s being targeted
- Commonly targeted roles: All employees (general awareness), Customer support teams, Marketing/communications teams (email platform admins), IT/Security teams managing SaaS/vendor access.
- Affected industries: Cryptocurrency / digital assets, Consumer electronics, Email/marketing platform providers (SaaS).
- Attack channels: email, website.
- Impersonated: Trezor (official newsletter channel).
Red flags to watch for
- Asks for a wallet backup/recovery seed (a secret that should never be shared)
- Creates urgency/fear about immediate loss of funds due to a ‘serious’ bug
- Pushes users to a website/app outside normal, trusted workflows
Frequently asked questions
How did attackers send phishing emails through Trezor's real newsletter?
Attackers compromised Trezor's account at Brevo, the third-party email platform Trezor uses for newsletters, and used that access to send a fake security alert directly through Trezor's legitimate mailing system.
What did the phishing email claim?
It claimed Trezor devices were affected by a serious 'STM32 Entropy Bug' that could expose users' wallet seeds, creating urgency for recipients to act quickly.
What should someone do if they entered their wallet backup on the malicious site?
Trezor advises anyone who entered a wallet backup on the malicious site to immediately create a new wallet with a new recovery seed and transfer their funds to it.
How many people were affected by this campaign?
The campaign reached 347,000 subscribers, and about 2,500 clicked the malicious link before Trezor shut it down.
Read the video transcript
Imagine this: a scary security alert from Trezor, sent through Trezor’s real newsletter system… and it’s the phish. Attackers broke into Brevo, Trezor’s email vendor, and blasted 347,000 users a fake ‘STM32 Entropy Bug’ warning, pushing them to a site and app that calmly asked for one thing: your wallet backup, your recovery seed. Here’s the catch: Trezor said their devices and wallets weren’t hacked, and just clicking that link didn’t steal funds. The only way this works is if you actually type your recovery seed into that website or app. So if any email ever asks for a wallet backup or recovery phrase, no matter how legit it looks, do one thing: stop, close it, and go straight to the official app or website to check there instead.