Trezor says a phishing campaign targeting its customers earlier this week reached 347,000 email addresses after an attacker breached Brevo, its third-party newsletter provider.
The company said the incident began on September 9, 2026, when an unauthorized actor accessed Brevo's system and used 120 customer accounts, including Trezor's, to send emails. The messages falsely claimed that a vulnerability in the STM32 microcontrollers used in Trezor cold-storage wallets could expose wallet seeds to brute-force attacks.
The emails directed recipients to a malicious link that prompted them to download an app and enter their wallet backup. Trezor said it took down the domain used in the campaign within 20 minutes. As a result, the company said the campaign's impact was limited to 2,500 customers who clicked the link before it was disabled.
Trezor said the affected data was its opt-in newsletter database, covering roughly 347,000 email addresses. The company warned that the addresses could be used in future phishing attacks, but said no other Trezor system was affected. It has suspended its Brevo account to stop further email distribution.
Comments
0No comments yet. Be the first to comment.