Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Trezor Details Brevo Breach Behind Fake Security Alert

Trezor says attackers accessed its Brevo newsletter account to distribute a fake device vulnerability notice, while no wallet data or passwords were exposed.

Written By Sharmistha Suman
Edited by Sujha Sundararajan
Published 47 minutes ago·Updated 17 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Trezor Details Brevo Breach Behind Fake Security Alert

Key Highlights

  • Trezor confirmed that its Brevo email account was compromised and used to distribute a phishing campaign. 
  • The fraudulent message was sent to approximately 347,000 newsletter subscribers on September 9. 
  • The email falsely alleged an STM32 microcontroller defect that could cause devices to generate weak 40-bit seeds. 

Hardware wallet manufacturer Trezor confirmed that a phishing email was sent to its newsletter subscribers through a compromised third-party email provider. 

According to the details shared exclusively with The Crypto Times, the email, which carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability,” was sent on September 9, 2026. Trezor stated that it did not send the message and that the claim about its devices was false.

Detection and initial response

Trezor identified the phishing email shortly after it was sent at approximately 21:30 CEST on September 9. The company detected the activity through an internal security alert. Staff reviewed sending logs on Trezor’s Brevo account and confirmed that the messages had been dispatched through that account. A public warning was posted on X shortly afterward.

In its first public statement at 20:37 UTC on September 9, Trezor said its third-party email provider had been breached and described the STM32 entropy alert as a phishing attempt. The company instructed recipients not to click any links in the message. 

It also reported that it had taken down the domain used in the campaign and was investigating how attackers gained access to its legitimate mail infrastructure. A follow-up reply at 22:20 UTC reiterated that the email provider had been compromised.

Details of the phishing message

Recipients reported that the email displayed the sender name as “Trezor Security” and used help@trezor.io in the From field. The Return-Path pointed to mailing.trezor.io. Because the message travelled through Trezor’s own newsletter infrastructure, it passed standard authentication checks including SPF, DKIM, and DMARC.

The body of the email claimed a factory defect in the STM32 microcontroller and alleged that roughly one in four devices produced weak 40-bit seeds. It directed recipients to a page hosted on r.mailing.trezor.io. Some variants of the phishing page asked users to verify their xPub. Trezor has not published any product advisory matching the STM32 claim.

Scope of the incident and data exposure

Trezor identified the third-party provider as Brevo, which it uses for newsletter distribution. The Brevo account has been disconnected while the investigation continues.

According to the exclusive email shared by Trezor, the Brevo account held only opt-in newsletter subscriber email addresses. No other customer data was stored there. The company stated that it cannot confirm whether the list was exported. Until further information is received from Brevo, Trezor is treating all approximately 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing. Brevo’s system held no passwords, wallet data, or other personal information.

The initial email was sent to 347,000 customers. All of them have been contacted to inform them of the risk. Trezor took down the domain at the DNS level within 20 minutes, preventing the link from functioning for additional recipients. The company stated that clicking the link does not mean a user was compromised.

Additional measures taken

Trezor disabled the email-sending function to prevent further phishing messages. Warning messages were added to Trezor.io, Trezor Suite, community and support channels, and through direct email notifications.

In its statement to Crypto Times, Trezor said: “On 9 September, a phishing email with the subject line ‘Critical Security Alert: STM32 Entropy Vulnerability’ was sent to Trezor newsletter subscribers through our account with Brevo, the third-party provider we use for email. Trezor did not send it, and the claim it makes about Trezor devices is false.

We took the phishing domain offline, disconnected Brevo, and emailed everyone who received the message. We posted warnings on our official X account and community channels and added a warning banner to trezor.io and Trezor Suite.

Trezor devices, Trezor Suite, and Trezor’s own systems were not involved. Trezor does not hold wallet backups and never asks for one. Any message asking for a recovery phrase or backup is a scam.

We are working with Brevo to establish how our account was accessed. We are sorry this reached our users, and we will publish what we find.”

Trezor stated that it is following its incident process and would not comment further on whether the matter has been reported to authorities or cybersecurity agencies while the investigation remains open.

Also Read: MoneyGram Rolls Out In-App Stablecoin Spending Card

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Circle to End USDC and CCTP V1 Support on Noble by January 2027
Circle to End USDC and CCTP V1 Support on Noble by January 2027
Smartphone laying horizontally displaying the a16z crypto logo in green on a black screen.
a16z Says Permissionless Blockchains Can Meet U.S. AML Rules 
Hand holding a smartphone displaying the MoneyGram app logo against a red MoneyGram background.
MoneyGram Rolls Out In-App Stablecoin Spending Card
Hand holding a smartphone displaying the BitGo logo with Hyperliquid branding in the background.
BitGo Enables Self-Custody Wallet Access to Hyperliquid Perpetuals
White House Crypto Adviser Says Failed CLARITY Vote Could Delay Bill
White House Crypto Adviser Says Failed CLARITY Vote Could Delay Bill

Find Us on Socials

You may also like

Coinbase and Moov logos displayed on white illuminated blocks facing each other with a glowing "X" symbol in between.

Coinbase, Moov Partner to Add Stablecoin Payments Across 1,000+ Bank and Credit Union Network

Gold "Grain Backed Asset" coin stamped with a wheat sheaf sitting in loose grain beside a spilled burlap sack, positioned next to a tablet displaying "Tokenized Grain Asset" on an active dashboard

India’s Arya.ag Tests Tokenized Grain Receipts on Avalanche Chain

Reserve Bank of India seal alongside Indian national flag, REC and Larsen & Toubro "Tokenized Corporate Bonds" plaques, and a gold CBDC coin on stacked coins

India’s First tokenized Corporate Bonds Go Live; Secondary Market Yet to Open

Jon Cunliffe, Former Bank of England Deputy Governor

Former BoE Deputy Governor Jon Cunliffe Joins Fnality Board

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information