Key Highlights
- Trezor confirmed that its Brevo email account was compromised and used to distribute a phishing campaign.
- The fraudulent message was sent to approximately 347,000 newsletter subscribers on September 9.
- The email falsely alleged an STM32 microcontroller defect that could cause devices to generate weak 40-bit seeds.
Hardware wallet manufacturer Trezor confirmed that a phishing email was sent to its newsletter subscribers through a compromised third-party email provider.
According to the details shared exclusively with The Crypto Times, the email, which carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability,” was sent on September 9, 2026. Trezor stated that it did not send the message and that the claim about its devices was false.
Detection and initial response
Trezor identified the phishing email shortly after it was sent at approximately 21:30 CEST on September 9. The company detected the activity through an internal security alert. Staff reviewed sending logs on Trezor’s Brevo account and confirmed that the messages had been dispatched through that account. A public warning was posted on X shortly afterward.
In its first public statement at 20:37 UTC on September 9, Trezor said its third-party email provider had been breached and described the STM32 entropy alert as a phishing attempt. The company instructed recipients not to click any links in the message.
It also reported that it had taken down the domain used in the campaign and was investigating how attackers gained access to its legitimate mail infrastructure. A follow-up reply at 22:20 UTC reiterated that the email provider had been compromised.
Details of the phishing message
Recipients reported that the email displayed the sender name as “Trezor Security” and used help@trezor.io in the From field. The Return-Path pointed to mailing.trezor.io. Because the message travelled through Trezor’s own newsletter infrastructure, it passed standard authentication checks including SPF, DKIM, and DMARC.
The body of the email claimed a factory defect in the STM32 microcontroller and alleged that roughly one in four devices produced weak 40-bit seeds. It directed recipients to a page hosted on r.mailing.trezor.io. Some variants of the phishing page asked users to verify their xPub. Trezor has not published any product advisory matching the STM32 claim.
Scope of the incident and data exposure
Trezor identified the third-party provider as Brevo, which it uses for newsletter distribution. The Brevo account has been disconnected while the investigation continues.
According to the exclusive email shared by Trezor, the Brevo account held only opt-in newsletter subscriber email addresses. No other customer data was stored there. The company stated that it cannot confirm whether the list was exported. Until further information is received from Brevo, Trezor is treating all approximately 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing. Brevo’s system held no passwords, wallet data, or other personal information.
The initial email was sent to 347,000 customers. All of them have been contacted to inform them of the risk. Trezor took down the domain at the DNS level within 20 minutes, preventing the link from functioning for additional recipients. The company stated that clicking the link does not mean a user was compromised.
Additional measures taken
Trezor disabled the email-sending function to prevent further phishing messages. Warning messages were added to Trezor.io, Trezor Suite, community and support channels, and through direct email notifications.
In its statement to Crypto Times, Trezor said: “On 9 September, a phishing email with the subject line ‘Critical Security Alert: STM32 Entropy Vulnerability’ was sent to Trezor newsletter subscribers through our account with Brevo, the third-party provider we use for email. Trezor did not send it, and the claim it makes about Trezor devices is false.
We took the phishing domain offline, disconnected Brevo, and emailed everyone who received the message. We posted warnings on our official X account and community channels and added a warning banner to trezor.io and Trezor Suite.
Trezor devices, Trezor Suite, and Trezor’s own systems were not involved. Trezor does not hold wallet backups and never asks for one. Any message asking for a recovery phrase or backup is a scam.
We are working with Brevo to establish how our account was accessed. We are sorry this reached our users, and we will publish what we find.”
Trezor stated that it is following its incident process and would not comment further on whether the matter has been reported to authorities or cybersecurity agencies while the investigation remains open.
Also Read: MoneyGram Rolls Out In-App Stablecoin Spending Card
