Phishing Campaign Exploited Trezor’s Brevo Newsletter Account

An attacker exploited Trezor’s account with newsletter service Brevo. The phishing email urged recipients to download an app and enter their wallet seed.

A Trezor phishing campaign via Brevo reached approximately 347,000 subscribers to the hardware cryptocurrency wallet manufacturer’s newsletter. Trezor said that on September 9, 2026, an unauthorized actor exploited its account with external email campaign provider Brevo and sent a phishing message from it.

The email had the subject “Critical Security Alert: STM32 Entropy Vulnerability” and, because it was sent through a trusted newsletter channel, could have appeared legitimate to recipients. Trezor also said that its own systems, devices, wallets, and user accounts were not affected by the incident.

Trezor phishing campaign requested wallet seed

The message contained a link urging recipients to download an app and enter their wallet backup, or seed. The seed is sensitive information that allows access to the cryptocurrency in a wallet to be restored. Giving it to an attacker can lead to the takeover of all funds protected by that backup.

According to Trezor, simply opening the link does not put funds at risk. The immediate risk arises only when a user enters the seed on a fraudulent website or into a malicious app.

The company deactivated its account with Brevo and disabled the domain used for the malicious link at the DNS level. It said it took these steps within 20 minutes. Approximately 2,500 people opened the link before it was blocked.

It is unclear whether the contact list was leaked

It has not been confirmed whether the attacker exported the list of email addresses from Brevo. As a precaution, Trezor is working on the assumption that the attacker knows all approximately 347,000 addresses contacted. Recipients may therefore face further targeted phishing attempts that could follow up on this campaign.

The mechanism by which the Brevo account was compromised is not publicly known at this time. The scope of the incident among other customers of the email platform has also not been confirmed. Cases of cryptocurrency theft directly resulting from this campaign have likewise not been confirmed.

What email recipients should do

  • Never enter a seed, recovery phrase, or any of its individual words into a web form, app, or email.
  • Do not open links from the message in question or download the app it linked to.
  • If a user entered their seed on a fraudulent website or in an app, they should no longer consider it safe.
  • Be prepared for the possibility of further fraudulent messages, especially those using Trezor’s name or warnings about an alleged security problem.

The case highlights the risk posed by external marketing platforms: a manufacturer’s core infrastructure may remain untouched, but a compromised distribution channel can still allow attackers to reach a large number of users. Further information may come from Brevo’s statement on the cause of the incident, any possible contact-list leak, and the scope of affected accounts.

Sources

  • Trezor – Confirms the newsletter account compromise, approximately 347,000 recipients, the phishing content, disabling of the link, and the status of Trezor’s systems.
  • BleepingComputer – Corroborates the campaign’s scope and the figure of approximately 2,500 clicks before the link was blocked.
  • SecurityWeek – Corroborates that Trezor customers received phishing emails after the incident at Brevo.

Verified and updated: 09/11/2026 15:26

Sharing