The second major data breach affecting Trezor customers in as many months has exposed the personal information of hardware crypto wallet users to a sophisticated phishing campaign, this time through a compromised third-party email marketing provider that allowed hackers to send approximately 347,000 fraudulent messages directly to wallet owners. The incident, which originated not at Trezor itself but at Brevo, a marketing technology company the hardware wallet maker uses to distribute newsletters, represents an escalating pattern of supply chain attacks targeting one of the most trusted names in cryptocurrency self-custody. With stolen wallet passwords enabling irreversible theft of funds on public blockchains, and with the physical addresses of tens of thousands of crypto owners already compromised in a prior breach, the convergence of digital and physical threats facing Trezor’s user base has reached a critical inflection point.
How the Brevo Breach Enabled a Targeted Phishing Campaign Against Trezor Customers
According to a blog post published by Trezor, the security incident at Brevo unfolded when hackers gained unauthorized access to the email marketing platform and used it to send phishing emails that appeared to originate from the hardware wallet company itself. Brevo, in its own incident status post, confirmed that the attackers were able to compromise 138 accounts on its platform, abusing a permissions flaw that meant their access was, in the company’s words, “not properly scoped” and was “wrongly granted” to all organizations those accounts could reach.
This access gap allowed the attackers to send roughly 347,000 phishing emails to Trezor’s subscriber list. The emails carried subject lines such as “Critical Security Alert: STM32 Entropy Vulnerability,” a technical reference designed to create urgency and exploit the recipient’s concern about the security of their hardware device. The messages contained a malicious link that, when clicked, prompted the download of an application requesting the victim’s wallet backup password. In the world of self-custodied cryptocurrency, the wallet backup password, often referred to as a seed phrase or recovery seed, is the single most sensitive piece of information a user holds. A hacker in possession of this password can reconstruct a user’s wallet on any device and irreversibly drain all associated funds, with no recourse on the public blockchain.
Trezor was clear that none of its own products, wallets, or account systems were directly compromised in the incident. The breach was confined to Brevo, the third-party email provider. But the distinction offers little comfort to the roughly 347,000 users whose email addresses are now confirmed to be in the hands of malicious actors. In a statement accompanying the disclosure, Trezor warned that those email addresses may be used again for future phishing attacks, a sobering acknowledgment that this incident is not a one-and-done event but a persistent risk vector.
What Is a Third-Party Supply Chain Attack and Why Does It Keep Happening to Crypto Companies?
The Brevo incident is a textbook example of a supply chain attack in the cybersecurity industry. Instead of attempting to breach Trezor’s own hardened systems directly, the attackers targeted a vendor that Trezor relies on for a routine business function, in this case, email newsletter distribution. The logic is straightforward: marketing platforms, customer support portals, shipping partners, and analytics tools often hold aggregated data from multiple client companies, and a single flaw in the vendor’s access controls can expose the users of every company that uses that vendor.
This is not an isolated phenomenon in the crypto industry. Hardware wallet companies, exchanges, and decentralized finance platforms are increasingly reliant on a web of third-party vendors for logistics, marketing, compliance, and customer service. Each vendor represents a potential entry point for attackers who may lack the sophistication or resources to go after the primary target directly. The 347,000 phishing emails sent via Brevo were, in effect, a force multiplier: the attackers did not need to phish each user individually. They compromised one vendor, gained access to a mailing list, and let the email infrastructure do the rest.
For Trezor, this is the second such incident in rapid succession, and it raises serious questions about the company’s vendor management and risk assessment processes. A breach at a single vendor might be dismissed as bad luck. Two breaches at two different vendors within weeks suggests a pattern that demands systemic reevaluation. Trezor has stated that it is reevaluating its relationships with its vendors, but for the users already affected, the damage is done.
The ShipMonk Breach: How 81,000 Crypto Owners Had Their Physical Addresses Exposed
The Brevo phishing campaign cannot be fully understood without examining the breach that preceded it. In August, Trezor alerted customers that ShipMonk, a third-party shipping and fulfillment partner, had been compromised in a data breach. The ShipMonk incident exposed the names, phone numbers, email addresses, and postal addresses of at least 81,000 individuals who had purchased and received Trezor hardware wallets. The number was later updated to reflect the scale of the exposure, and it became clear that a significant portion of Trezor’s customer base had their personal identifying information, including home addresses, leaked to attackers.
The timing of these two incidents is critical. Attackers now possess, for at least a subset of Trezor customers, both email addresses from the Brevo incident and physical addresses from the ShipMonk breach. This combined data set is exceptionally dangerous because it enables multi-vector attacks that blend digital phishing with physical intimidation and fraud.
In the weeks following the ShipMonk breach, some Trezor customers reported receiving letters sent through postal mail that claimed to be from Trezor. These letters featured QR codes that, when scanned, opened fake web pages designed to steal the victim’s crypto wallet password. The use of physical mail as a phishing vector is a notable escalation. It exploits the inherent trust that people place in postal correspondence, a medium that has not yet been thoroughly saturated with the skepticism that most users now apply to email.
Wrench Attacks and Targeted Violence: The Physical Threat to Crypto Owners
The convergence of digital and physical risk vectors in these back-to-back breaches places Trezor customers in a category of vulnerability that extends far beyond typical identity theft. When attackers know a person’s name, phone number, email address, and home address, and when they also know that this person likely holds cryptocurrency on a hardware wallet, the risk of targeted physical violence becomes a concrete and serious concern.
In cybersecurity circles, what security professionals call a “wrench attack” refers to a scenario in which an attacker physically confronts a victim and extracts passwords, keys, or access credentials under threat of violence. The name comes from the blunt instrument that might be used to compel cooperation, but the concept applies broadly to any situation where physical proximity and coercive force replace technical hacking. For crypto owners who self-custody significant amounts of wealth, a wrench attack is arguably one of the hardest threats to defend against. No amount of encryption, multi-factor authentication, or cold storage security can protect a seed phrase that a user is forced to reveal at gunpoint.
The data exposed in the ShipMonk and Brevo breaches effectively hands attackers a curated list of targets who are far more likely to hold substantial crypto assets than the general population. Trezor users, by definition, are people who have taken active steps to secure their digital wealth using hardware wallets, a choice that typically correlates with higher asset values and a deeper understanding of crypto self-custody. The attackers now have the information they need to find these individuals, and they have demonstrated a willingness to use unconventional methods, including postal mail, to reach them.
This is not a theoretical risk. The crypto industry has seen documented cases of physical attacks targeting wallet holders, including home invasions, kidnappings, and robberies. The data breaches at Trezor’s vendors have effectively amplified this risk by orders of magnitude, providing malicious actors with a structured, searchable database of potential victims.
How the Phishing Attack Worked: Technical Mechanics and User Vulnerabilities
The phishing campaign that originated from the Brevo breach was carefully engineered to exploit both technical vulnerabilities and human psychology. The email subject line, “Critical Security Alert: STM32 Entropy Vulnerability,” would have resonated powerfully with technically literate Trezor users. The STM32 is a family of microcontroller chips commonly used in hardware devices, including some hardware wallets. The reference to an entropy vulnerability, which is a genuine class of security flaw affecting random number generation in cryptographic systems, gave the message an air of technical authenticity that a more generic phishing subject line would have lacked.
When a recipient clicked the embedded link, the destination served a download of an application that, when executed, requested the user’s wallet backup password. This is the moment at which digital theft becomes irreversible. The wallet backup password, often encoded as a 12-word or 24-word seed phrase using the BIP-39 standard, is the single point of failure for any self-custodied cryptocurrency wallet. With this seed phrase, an attacker can regenerate the private keys for the wallet on any device, sign transactions, and transfer the funds to an address under their control. There is no central authority to reverse the transaction, no bank to call, no fraud department to file a claim. On the Bitcoin blockchain and most other public blockchains, a confirmed transaction is final.
The attackers chose their target vector wisely. Rather than attempting to compromise Trezor’s own systems, they went after the email list, a far more accessible target. The phishing emails leveraged the trust that users already had in Trezor’s official communications, a trust that had been built over years of legitimate newsletters and product updates. This trust, once broken, is extraordinarily difficult to rebuild, and it may be the most significant long-term casualty of the breach.
What Brevo Did Wrong: The Access Control Failure That Enabled the Attack
Brevo’s own account of the incident points to a fundamentally avoidable failure in access control. The company stated that the hackers were able to access 138 accounts because their permissions were “not properly scoped” and were “wrongly granted” to all organizations those accounts could reach. This is a technical way of saying that Brevo did not adequately limit what each account could do or see. In a well-designed permission system, an account belonging to one Brevo customer should have access only to that customer’s data and mailing lists. The flaw that the attackers exploited allowed accounts to reach beyond their intended boundaries, effectively giving them a master key to a wide swath of Brevo’s client data.
This type of vulnerability, known as a privilege escalation or an authorization bypass, is one of the most fundamental security failures that a software platform can suffer. It indicates that Brevo’s internal access control model lacked the granularity to enforce the principle of least privilege, the security tenet that holds that any user or account should have only the minimum permissions necessary to perform its function. When a platform serves as many diverse clients as Brevo does, the failure to properly scope permissions can trigger a cascading exposure across multiple organizations simultaneously.
For Trezor, the immediate consequence is clear. But the broader implication for any company that uses Brevo or similar marketing platforms is equally unsettling. If Brevo’s access controls can be bypassed in this way, every company using the platform is potentially vulnerable to a similar attack. Brevo has not disclosed whether it has fully closed the vulnerability or whether it has identified all 138 compromised accounts, but the incident serves as a stark reminder that a company’s security posture is only as strong as the weakest vendor in its supply chain.
What Trezor Customers Should Do Now: Practical Steps for Digital and Physical Protection
For the 347,000 Trezor customers whose email addresses were exposed in the Brevo incident, and for the 81,000 whose physical addresses were exposed in the ShipMonk breach, the priority is to take immediate defensive action. The first and most critical step is to recognize that any email or physical letter claiming to be from Trezor that asks for a wallet backup password, seed phrase, or PIN is a phishing attempt. Trezor, like every legitimate hardware wallet company, will never ask for this information. The seed phrase should never be entered into any website, application, or email reply, and it should never be typed into a computer or phone under any circumstances. The only safe use of a seed phrase is to restore a wallet on a hardware device that is being used in a secure, offline environment.
Users should also enable additional layers of security on their Trezor devices and accounts. Trezor devices support PIN codes and passphrase-based wallets, and users who have not yet set up a passphrase should consider doing so. A passphrase acts as a 25th word on top of the standard 12-word or 24-word seed phrase, and it effectively creates a completely separate wallet that cannot be accessed without the passphrase, even if the seed phrase is compromised. This is one of the most effective countermeasures against seed phrase theft, and it is native to the Trezor ecosystem.
On the physical security front, the combination of email exposure and address exposure warrants a higher level of vigilance. Trezor customers who hold substantial crypto wealth should review their personal security practices, including the physical security of their homes, the privacy of their mailing address, and the level of information they share online. In some cases, it may be worth considering the use of a P.O. box or a virtual mailing address for future hardware wallet purchases and for any other correspondence with crypto-related businesses. The goal is not to live in fear but to disrupt the link between one’s identity and one’s crypto holdings, a link that these breaches have strengthened for the attackers.
The Broader Implications for the Cryptocurrency Self-Custody Ecosystem
The back-to-back breaches at Trezor’s vendors underscore a structural vulnerability that extends far beyond one company. The entire hardware wallet industry, and by extension the broader cryptocurrency self-custody ecosystem, depends on a complex web of third-party vendors for manufacturing, logistics, marketing, payments, and customer support. Each vendor represents a potential point of failure, and the security practices of these vendors vary widely. A hardware wallet may be an engineering marvel of cryptographic security, but its users remain exposed through the mundane business processes of ordering, shipping, and receiving.
This tension between product-level security and business-level vulnerability is one of the most underappreciated risks in the cryptocurrency space. Users obsess over the security of their seed phrases, the integrity of their hardware, and the strength of their passphrases, but they rarely think about the security practices of the shipping company that delivers their device or the email platform that sends them newsletters. The breaches at Trezor’s vendors reveal that the attack surface for a hardware wallet user is far larger than the device itself. It includes every company that touches the user’s data anywhere along the purchase and support journey.
The industry as a whole would benefit from adopting more rigorous vendor security standards, including mandatory security audits, data minimization policies, and contractual requirements for timely breach notifications. Some companies have begun to move in this direction, but the pace of change is slow relative to the speed at which attackers adapt. Trezor, to its credit, has been transparent about both incidents, publishing detailed blog posts and issuing public warnings. That transparency is essential, but it must be accompanied by structural changes that reduce the likelihood of future breaches.
Why This Breach Matters Beyond Trezor: A Warning for Every Crypto User
For the broader crypto community, the Trezor breaches should serve as a cautionary tale about the hidden risks of self-custody. Self-custody is often described as the gold standard of crypto security, and it is, in principle, far safer than leaving funds on an exchange. But self-custody is not a silver bullet. It requires users to manage not just their private keys but also their personal data, their communication channels, and their physical security. The Trezor incidents demonstrate that even the most security-conscious users can be exposed through channels they never considered.
The phishing emails sent via Brevo were effective precisely because they exploited the trust that users placed in Trezor’s brand. The letters mailed to ShipMonk breach victims exploited the trust that users placed in physical mail. In both cases, the attackers did not need to break Trezor’s cryptography. They only needed to break the trust relationship between Trezor and its users. That trust, once damaged, may never fully recover, not just for Trezor but for the entire hardware wallet industry.
For attackers, the calculus is shifting. The barriers to entry for crypto theft have historically been technical: you needed to understand blockchain protocols, exploit smart contract vulnerabilities, or crack private keys. The Trezor breaches suggest that a simpler, more scalable approach is increasingly viable: steal personal data from third-party vendors, use that data to target wallet owners with phishing attacks, and let the victims hand over their own funds through deception. This is not a high-tech attack. It is a human attack, and it is far harder to defend against with technology alone.
Trezor’s Response: Reevaluating Vendor Relationships and Restoring User Trust
In its disclosures, Trezor has made clear that it is taking the incidents seriously. The company stated that it is reevaluating its relationships with its vendors, a process that will likely involve stricter security requirements, more frequent audits, and possibly a reduction in the number of third-party partners the company relies on. Trezor has also warned customers that their email addresses may be used again in future phishing campaigns, a necessary but unsettling admission that the exposure is permanent and cannot be undone.
The company’s decision to be transparent about both breaches, even when the incidents originated at vendors rather than at Trezor itself, is commendable. Many companies would have downplayed the severity or shifted blame entirely. Trezor has instead acknowledged the pattern, warned its users, and committed to structural changes. Whether those changes will be sufficient to prevent a third incident remains to be seen, but the company has at least signaled that it understands the gravity of the situation.
For users, the most important takeaway is that the landscape of threats has changed. The era in which crypto security was purely about private keys and cryptography is over. Security now also means operational security: protecting one’s personal information, being skeptical of every communication, and recognizing that the weakest link in any self-custody setup may have nothing to do with the wallet itself. The 347,000 Trezor customers whose email addresses were exposed are not victims of a cryptographic failure. They are victims of a supply chain failure, and the lessons from that failure apply to every person who holds cryptocurrency in any form, on any platform, anywhere in the world.