Trezor said on Sept. 10, 2026, that a breach at email provider Brevo enabled attackers to send a malicious message to roughly 347,000 newsletter subscribers, turning a routine marketing channel into a direct path for a cryptocurrency phishing campaign.

The hardware-wallet company disclosed that the Sept. 9, 2026, incident did not compromise its devices, wallet software or account systems. The attackers instead used access to Brevo’s platform to send email from a legitimate Trezor communications account. The message promoted a supposed “STM32 Entropy Vulnerability” and directed recipients to download an application that requested their wallet backup.

Trezor said it disabled email sending, suspended its Brevo account and took down the malicious domain within 20 minutes. About 2,500 recipients had clicked the link before it was disabled, according to the company. Trezor said that clicking alone did not expose funds; the immediate danger applied to anyone who entered a wallet backup into the fraudulent application.

A trusted channel became the attack surface

The incident is more consequential than a conventional spoofed-email campaign because the message came through infrastructure used for authentic customer communications. That can allow a malicious message to pass the technical checks and visual cues customers are trained to use when evaluating email.

TechCrunch independently reported the campaign and noted that it was the second third-party breach affecting Trezor customers in recent weeks. An earlier incident at shipping provider ShipMonk exposed customer contact and delivery information. Trezor said it is reviewing its vendor relationships and security requirements.

Brevo reported that attackers gained access to customer accounts through an authorization flaw that granted access more broadly than intended. Trezor’s notice said the affected marketing system held email addresses but not wallet passwords or wallet data.

The business risk sits outside the product

For executives, the episode is a reminder that customer trust depends on the security of the full communications and commerce stack—not only the core product. Marketing platforms, fulfillment firms and support systems can hold enough access or identity data to create a convincing attack even when the primary service remains secure.

That makes vendor oversight a brand and customer-experience responsibility as much as a technical one. Security reviews should cover who can send messages from an official domain, how third-party permissions are scoped, how quickly access can be revoked and whether customers can verify urgent notices independently.

Trezor advised customers not to enter a wallet backup on a website or share it with anyone. Anyone who entered a backup after following the malicious link should move funds to a new wallet immediately, the company said.

Sources: Trezor’s Sept. 10 incident notice, Brevo’s incident write-up and TechCrunch’s independent reporting.