Trezor said on September 9 that attackers used a breach at its third-party email provider to send a phishing message to its newsletter audience, exposing a potential long-term scam risk for roughly 347,000 email addresses. The hardware-wallet maker said its wallet systems were not compromised, but warned recipients not to click a link in an email titled “Critical Security Alert: STM32 Entropy Vulnerability.”
The campaign turned Trezor’s ordinary customer-email channel into a vehicle for a fraudulent security notice. While the immediate operation was taken down, Trezor has treated the newsletter addresses as potentially known to the attackers and therefore usable in future, more targeted phishing attempts.
Brevo SAML flaw gave attackers access to customer email accounts
The intrusion originated at Brevo, the email-services provider used by Trezor. In an incident write-up, Brevo said an attacker exploited a flaw in its SAML single-sign-on system to access 138 customer accounts.
Six of those accounts were used to distribute phishing emails, while contacts were exported from 43 accounts, according to Brevo. The provider said it closed the access route at 08:30 UTC on September 10.
The disclosed figures cover the wider Brevo incident rather than Trezor alone. They nevertheless show that the attackers had access not simply to a standalone contact list, but to customer email accounts capable of sending messages through familiar business infrastructure.
False STM32 alert used Trezor’s sender infrastructure
The email falsely claimed that roughly one in four Trezor devices had a hardware defect involving weak entropy, which Trezor said was false, and presented a link as a security response to the purported problem.
The Register reported that the emails came through legitimate Trezor email infrastructure, making them more likely to pass routine sender-authentication checks. That removed a warning sign recipients often rely on when assessing unsolicited crypto-related messages.
Trezor’s September 9 public notice identified the message subject line and told users not to interact with the embedded link. The company said the incident was a compromise of its third-party provider’s mail-server infrastructure rather than its wallet systems.
About 2,500 recipients reached a site seeking wallet backups
About 2,500 recipients clicked the malicious link before Trezor took the associated website offline, according to SecurityWeek. The outlet reported that the company removed the site about 20 minutes after detecting the campaign.
The linked application asked users for their wallet backups. A wallet backup can enable control of the associated funds, meaning anyone who entered one into a malicious application could face irreversible theft.
The available disclosures do not establish how many, if any, recipients submitted a backup. They do draw a clear line between the contact-list exposure and the more serious risk created if a recipient provided recovery material on the phishing site. Trezor said the newsletter database itself did not store wallet backups or passwords.
The 347,000-address list can fuel repeat phishing attempts
Cointelegraph reported that Trezor’s newsletter database contained approximately 347,000 addresses targeted in the campaign and that Trezor considered them potentially known to the attacker and reusable for future phishing.
Although Trezor said the list held no passwords or wallet backups, the exposure can outlast the original fraudulent website as a channel for follow-on impersonation. Brevo said it had blocked the SAML route used in the initial compromise.