🇺🇸 United States · English ← Edition home
bitcoin

Trezor Phishing Attack Exposed a Hidden Brevo Flaw — Here’s the One Security Rule That Can Save Your Crypto

For readers in the United States

Author: Aditya Shaw · Independent coverage. Corrections / Contact

Trezor Phishing Attack Exposed a Hidden Brevo Flaw — Here’s the One Security Rule That Can Save Your Crypto
Trezor Phishing Attack Exposed a Hidden Brevo Flaw — Here’s the One Security Rule That Can Save Your Crypto

A major phishing campaign targeting Trezor users has revealed a surprisingly important lesson for the crypto industry: sometimes the biggest security risk is not the hardware wallet itself, but the trusted systems surrounding it.

In the latest incident, attackers abused a security weakness in Brevo’s single sign-on and authorization system to reach customer organizations connected to legitimate users. That access was then used to distribute convincing phishing emails through trusted infrastructure associated with companies including Trezor, BitBox and CoinTracking.

The encouraging part is equally important: Trezor says its hardware wallets, wallet backups and internal systems were not compromised. For users who never entered their recovery phrase into the malicious application, the incident does not mean their crypto was automatically stolen.

What Happened in the Trezor Phishing Attack?

The incident began with a compromise at Brevo, a third-party email marketing platform used by Trezor for newsletters.

According to Brevo's postmortem reported by Crypto.news, the attacker exploited an authorization boundary involving accounts connected to multiple organizations. The attacker created a Brevo organization, enabled single sign-on and invited legitimate users into that organization. A permissions failure then allowed access to other organizations those users were authorized to reach.

That distinction matters. This was not simply a case of someone guessing a Trezor password and breaking directly into Trezor's wallet infrastructure. Instead, the attackers found a weakness in a trusted third-party service that sat between the companies and their email subscribers.

Brevo said the incident affected 138 customer accounts. Six accounts were used to send phishing emails, while contact information was exported from 43 accounts.

Why the Fake Trezor Email Looked So Convincing

This is where the attack becomes particularly interesting.

Traditional phishing attacks often rely on obvious warning signs: a strange sender address, a fake domain, poor grammar or a suspicious-looking link. This campaign had a major advantage because attackers were able to use legitimate email infrastructure connected to the affected organizations.

That meant the message could appear far more trustworthy than an ordinary spoofed email. Crypto.news reported that the fraudulent messages could pass normal email authentication checks because they were sent through legitimate mailing infrastructure.

The Trezor campaign used the alarming subject line "Critical Security Alert: STM32 Entropy Vulnerability." Recipients were told about a supposed hardware security problem and encouraged to take action.

The real objective was much simpler: persuade users to provide their wallet backup or recovery phrase.

That is the critical point every crypto user should remember. A phishing email does not need to break a hardware wallet if it can convince the owner to hand over the information needed to control the wallet.

How Many Trezor Users Were Reached?

Trezor said its Brevo account contained approximately 347,000 opt-in newsletter addresses. The initial phishing message was sent to that subscriber base. Around 2,500 people accessed the malicious link before Trezor took the domain offline at the DNS level, according to the company.

Trezor is treating the entire newsletter database as potentially known to the attacker while the investigation continues. Importantly, the company said Brevo did not contain wallet backups, passwords or other wallet-control information.

That creates a very different risk profile from a direct wallet breach. The stolen or potentially exposed information is valuable primarily because it can help attackers identify real users and launch more convincing follow-up scams.

Was Trezor Actually Hacked?

No — not in the sense most users are probably imagining.

Trezor has stated that the breach occurred at its third-party email provider and that its own wallet systems and products were not compromised. The company's official guidance also makes clear that users who did not enter their wallet backup into the malicious application remain safe from this particular phishing attack.

This is an important distinction because the word "hack" can create unnecessary panic in crypto markets.

A hardware wallet can remain technically secure while its users are still exposed to social engineering. In fact, that is one of the biggest challenges facing self-custody today: the cryptography can work exactly as designed while the human being holding the wallet is manipulated.

The One Rule Trezor Users Should Never Break

There is one rule that cuts through almost every variation of this attack:

Never enter your wallet recovery phrase into a website, email form, desktop application or online verification tool because someone told you to.

Trezor will not ask users to provide their wallet backup through an email link. The company's security guidance says that requests for a wallet backup, PIN, password or security code should be treated as scams.

This rule is powerful because it works even when the attacker has done everything else correctly.

The email can look real. The logo can look real. The sender can appear legitimate. The domain can look familiar. The message can even arrive through an authenticated mailing system.

But the recovery phrase remains the line that should never be crossed.

What If You Only Clicked the Trezor Phishing Link?

Trezor says clicking the malicious link by itself does not mean that a user's funds have been compromised.

The critical danger begins when someone enters their wallet backup or recovery phrase into the malicious application or another online location. Trezor advises users who entered their wallet backup to move their funds to a new wallet immediately.

If you clicked the link but did not enter your recovery phrase, the situation is considerably more positive. Delete the message, avoid interacting with the phishing page again, and use only official Trezor channels for future security information.

Why This Attack Is Bigger Than Trezor

The most valuable lesson here extends well beyond one hardware-wallet company.

Modern businesses depend on layers of third-party technology: email providers, cloud platforms, customer relationship systems, analytics services, payment processors and authentication platforms. Each layer can become part of the overall security boundary.

That means companies increasingly need to think about ecosystem security, not simply internal security.

The Brevo incident is a strong example. The attackers did not need to compromise every company individually. A weakness in the permission model of a shared service created a path into multiple customer organizations.

For the crypto industry, this is especially important because an ordinary marketing email can ultimately become a financial attack vector.

Trezor, BitBox and CoinTracking Were All Caught in the Same Wave

The incident was not limited to Trezor.

Brevo's investigation identified access involving accounts used by Trezor, BitBox and CoinTracking. BitBox users were also warned about fraudulent messages, while CoinTracking customers received a phishing lure focused on refreshing API keys.

This suggests a broader pattern: once attackers obtain access to trusted communication infrastructure, they can tailor the same basic strategy to different audiences.

For a hardware-wallet customer, the lure may be a fake device-security warning. For a crypto tax user, it may be an API-key alert. For another financial service, it could be a fake account verification notice.

The packaging changes. The objective remains the same: create urgency and make the victim act before thinking.

The Positive Security Lesson for Crypto Users

There is a surprisingly positive takeaway from this incident.

Self-custody still gives users a powerful layer of protection because the attacker ultimately needs something the legitimate user controls. If the recovery phrase never leaves the owner's secure environment, a phishing email alone cannot simply transfer the assets.

That makes security discipline incredibly valuable.

Instead of trying to identify every possible scam message, users can build a much simpler habit: never use an email as the starting point for a high-risk crypto action.

If an email says your wallet is vulnerable, close the message. Open the official wallet software or manually navigate to the company's official website. Check the announcement independently.

That small behavioral change can defeat an impressive amount of social engineering.

5 Simple Steps to Stay Safe After the Trezor Breach

  1. Do not enter your recovery phrase online. This is the most important rule.
  2. Do not trust urgent security emails automatically. Verify the warning through an official channel.
  3. Delete suspicious Trezor messages. Do not continue interacting with the links or attachments.
  4. If you entered your recovery phrase, act immediately. Move funds to a newly generated secure wallet and treat the old recovery phrase as compromised.
  5. Keep security information independent. A genuine company announcement should be verifiable without relying on the suspicious email itself.

What This Means for the Future of Crypto Security

The crypto industry has spent years improving hardware security, cryptography and transaction signing. Those protections remain essential, but incidents like this show that the next major security improvements may need to focus just as heavily on communication systems and human behavior.

Companies should assume that newsletter platforms, support systems and other third-party services can become attractive targets. Strong vendor security, tighter authorization boundaries, multi-organization access controls and rapid incident response are no longer optional extras for companies serving crypto users.

Users, meanwhile, can adopt an even simpler defense: slow down when a message tries to create urgency.

That may be the most underrated security tool in crypto.

Bottom Line: Your Recovery Phrase Is Still Your Strongest Defense

The Trezor phishing attack is a serious warning, but it is not a reason for every Trezor owner to panic.

The facts available so far point to a breach of a third-party email platform and an authorization weakness at Brevo, rather than a compromise of Trezor's hardware wallets themselves. Trezor moved quickly to disable the affected email function, take down the malicious domain and warn subscribers.

The clearest lesson is also the most reassuring one: attackers can imitate a trusted message, but they cannot turn a phishing email into your recovery phrase unless you give it to them.

For crypto holders, that is a powerful reason to stay calm, verify independently and keep the recovery phrase exactly where it belongs — offline and under the owner's control.

Frequently Asked Questions

Was Trezor directly hacked?

No. Trezor said the incident occurred at Brevo, its third-party email provider, and that Trezor's wallet systems, products and wallet backups were not compromised.

What was the Brevo security flaw?

Brevo said the attacker exploited an authorization boundary involving users connected to multiple organizations. The flaw allowed access beyond the organization controlled by the attacker and exposed access to other organizations those users could reach.

How many Trezor subscribers were targeted?

Trezor said approximately 347,000 newsletter addresses were held in the affected Brevo account, and the initial phishing email was sent to that subscriber base. Around 2,500 people accessed the malicious link before the domain was taken down.

Can clicking the phishing link alone steal my crypto?

Trezor says clicking the link alone does not mean your funds were compromised. The critical risk arises if you entered your wallet backup or recovery phrase into the malicious application or another online location.

What should I do if I entered my Trezor recovery phrase?

Treat the recovery phrase as compromised and move your funds to a newly generated secure wallet immediately. Do not continue using the compromised recovery phrase.

Will Trezor ever ask for my recovery phrase by email?

No. Trezor explicitly warns users never to share their wallet backup and says legitimate Trezor communications will not ask for it.

What is the biggest lesson from the Trezor phishing attack?

The biggest lesson is that even highly convincing, legitimate-looking communications can be weaponized when trusted third-party infrastructure is compromised. The safest response is to verify independently and never disclose a wallet recovery phrase online.

Back to top