Trezor Reports Data Breach After Phishing Emails Sent to 347,000 Customers
Key Takeaways
- •A breach at Brevo, the third-party platform Trezor uses for newsletters, allowed an unauthorized actor to send phishing emails to 347,000 Trezor customers.
- •The fraudulent email, titled "Critical Security Alert: STM32 Entropy Vulnerability," tried to obtain wallet backups by prompting recipients to download an application and enter their backup.
- •Trezor took the attacker's domain down at the DNS level within 20 minutes, preventing the link from working for additional recipients and limiting access to about 2,500 people who had already clicked it.
- •Trezor suspended its Brevo account to stop further email distribution, confirmed no other Trezor systems were touched, and warned the exposed email addresses could be used in future phishing attacks.
- •The incident follows two disclosures involving Trezor's fulfillment partner ShipMonk, which exposed data from 11,742 customers and an additional 67,000 U.S. customers, amid similar breaches reported by Ledger and SafePal.

Trezor has warned that a breach at Brevo, the third-party marketing platform it uses to distribute newsletters, has exposed customers to phishing attacks.
The hardware wallet manufacturer said Wednesday that an unauthorized actor accessed Brevo’s system and sent emails to 347,000 Trezor customers. Brevo provides businesses with tools for sending customer communications.
The attackers used Trezor’s domain name, making the messages appear more credible. The phishing email contained a malicious link that asked recipients to download an application and enter their wallet backup.
Trezor said the message titled “Critical Security Alert: STM32 Entropy Vulnerability” was not legitimate and urged users not to click any links.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating… — Trezor (@Trezor) September 9, 2026
Trezor said it took down the domain at the DNS level within 20 minutes. The action prevented the link from working for additional recipients and limited access to the 2,500 people who had clicked it before the domain was disabled.
For affected users, Trezor described the immediate threat as a phishing attempt seeking wallet backups through a convincing message. The company said no other Trezor system was touched, but warned that the exposed email addresses could potentially be used in future phishing attacks.
“These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched,” Trezor said. The company added, “We have suspended the Brevo account to stop further email distribution.”
Trezor reminded users that it never asks customers for their wallet backups.
The incident follows two disclosures involving Trezor’s third-party fulfillment partner, ShipMonk. Last month, Trezor said data from 11,742 customers had been exposed after ShipMonk was targeted. The company said last week that an additional 67,000 U.S. customers had their names, email addresses, phone numbers, shipping addresses and order numbers leaked in the breach.
Other crypto wallet companies have also reported data-related incidents this year. Scammers obtained customer information through Global-e, the payment processor used by crypto wallet company Ledger, and used it to send phishing emails.
Last month, crypto wallet provider SafePal announced a breach involving unauthorized access to order information belonging to about 39,798 customers. The information included personal details such as names, addresses and purchase data.
The original report was published by Bitcoin Magazine and written by Mathew Di Salvo.