Scammers Target Hundreds of Thousands of Crypto Owners After Trezor Confirms Data Breach at Email Provider

Trezor Warns of Second Breach in Two Months Involving Third-Party Vendor

Hardware crypto wallet maker Trezor is warning customers for the second time in as many months that one of its third-party vendors was hacked, exposing customer data to attackers. In a blog post this week, the company disclosed that a cyberattack on Brevo โ€” a marketing technology company Trezor uses to send newsletters โ€” allowed hackers to send approximately 347,000 phishing emails to Trezor customers. The emails contained a malicious link purporting to originate from the wallet manufacturer.

How the Attack Works

The phishing link, when clicked, downloads an app that prompts the victim to enter their wallet backup password. According to Trezor, one of the email subject lines read: "Critical Security Alert: STM32 Entropy Vulnerability." With a stolen wallet password, an attacker can irreversibly drain the victim's funds on the public blockchain.

Brevo Acknowledges Misconfigured Access

Brevo said in an incident status post that hackers gained access to 138 Brevo accounts and used them to distribute the mass volume of phishing messages. Brevo attributed the breach to a flaw that caused the hackers' access to be "not properly scoped" โ€” meaning their accounts were "wrongly granted" permissions to reach all organizations within their reach.

A Familiar Pattern: Third-Party Vendor Risk

The incident highlights a common security risk in which attackers compromise data held by third-party companies that fulfill orders or facilitate customer communications. Trezor stated that none of its products, wallets, or account systems were affected by the Brevo incident.

Second Breach in Weeks: ShipMonk Incident Exposed 81,000 Customers

This is the second breach in recent weeks affecting Trezor. In August, the company alerted customers that one of its shipping partners had been compromised in a data breach. The incident at mailing company ShipMonk exposed the names, phone numbers, email addresses, and postal addresses of at least 81,000 people who purchased and received Trezor wallet hardware.

Physical Threats and "Wrench Attacks"

Data breaches of this nature can place crypto owners and other wealthy individuals at risk of targeted violence and so-called "wrench" attacks, which rely on physical coercion to extract passwords from victims. In the weeks following the ShipMonk breach, some individuals have received physical letters by mail claiming to be from Trezor. These letters include a QR code that, when scanned, opens a fake page designed to steal the victim's crypto wallet password.

Trezor Reassessing Vendor Relationships

Trezor said it is reevaluating its relationships with vendors and warned customers that their email addresses may be used again for future phishing attacks. The company urged users to remain vigilant and to verify communications directly through official Trezor channels.

via TechCrunch

Related