A vulnerability in email marketing platform Brevo allowed attackers to send a phishing email to roughly 347,000 subscribers of hardware wallet maker Trezor, the company confirmed, in an incident that also affected other cryptocurrency firms relying on the same service.
What Happened
Trezor told Cointelegraph that a flaw in Brevo's login system enabled bad actors to distribute a fraudulent email to its subscriber base. The company said it is now treating every affected address as compromised, describing each as "known to the attacker and possibly reusable for phishing."
The breach appears to extend beyond Trezor, with reports indicating that other crypto companies using Brevo — including hardware wallet competitor BitBox and portfolio tracking service CoinTracking — were caught up in the same campaign. That points to a platform-level weakness rather than an isolated targeting of a single brand.
Trezor is treating every affected email address as known to the attacker and possibly reusable for phishing.
Why It Matters
Phishing remains one of the most persistent threats facing crypto users, and hardware wallet customers are especially valuable targets because their email lists correlate with people who hold significant digital assets. When attackers can send messages that appear to originate from a trusted vendor, the risk of users being tricked into revealing recovery phrases or credentials rises sharply.
Trezor has repeatedly emphasized that it will never ask customers for their recovery seed, a core defense against these scams. Even so, the reuse of leaked addresses means affected subscribers could face ongoing phishing attempts long after the initial email.
What Users Should Do
Security experts advise anyone who may have received the message to stay cautious and follow basic protective steps:
- Never enter a recovery phrase online or share it in response to an email
- Verify sender addresses and avoid clicking links in unexpected messages
- Access wallet services only through official, manually typed website addresses
- Treat any urgent request tied to your wallet as a potential scam
The episode underscores how third-party service providers can become a weak link in the security chain, exposing crypto firms and their users even when the companies' own systems remain intact.
