Crypto Owners at Risk: Trezor’s Email Provider Data Breach Paves the Way for Scammers

Trezor, a maker of hardware cryptocurrency wallets, is alerting its users for the second time in two months about a security breach involving one of its service providers, which has led to customer data being compromised.
In a recent blog update, Trezor disclosed that a cyberattack on Brevo, the marketing technology firm it uses for sending newsletters, allowed attackers to distribute approximately 347,000 phishing emails to Trezor users, containing links disguised as communications from the wallet manufacturer.
If clicked, the malicious link prompts the unsuspecting user to download an application that requests their wallet backup password. Trezor mentioned that one of the subject lines from these emails read: “Critical Security Alert: STM32 Entropy Vulnerability.”
With access to a stolen wallet password, hackers can permanently remove a user’s funds from the public blockchain.
Brevo confirmed in an incident update that the attackers accessed 138 of its accounts to disseminate the large number of phishing messages. The company noted that the hackers exploited a vulnerability that allowed access that was “not properly scoped,” giving them rights that were “wrongly granted” across organizations that those accounts could reach.
This incident underscores a prevalent security issue, where hackers target data from third-party providers essential for customer transactions. Trezor emphasized that none of its own products, wallets, or account systems were compromised in this incident.
This marks the second significant security breach for Trezor in recent weeks, following an August alert regarding a data breach at one of its shipping partners, ShipMonk, which compromised personal information, including names and addresses, of over 81,000 customers who purchased Trezor wallets.
Such data breaches could expose cryptocurrency users and affluent individuals to risks of targeted violence or so-called “wrench” attacks, where individuals face physical coercion to extract passwords.
In the aftermath of the ShipMonk breach, some users received fraudulent letters claiming to be from Trezor, which included a QR code that redirects to a counterfeit webpage aimed at stealing their crypto wallet passwords.
Trezor indicated that it is reviewing its partnerships with vendors and cautioned users that their email addresses could be exploited for future phishing endeavors.



