Trezor is facing yet another security dilemma after its third-party email partner Brevo was breached, exposing Trezor users to a series of phishing emails.
The wallet maker revealed that hackers were able to access its email domain, which it’s since taken down, and is now launching an investigation.
Scammers warned Trezor newsletter subscribers of a “Critical Security Alert: STM32 Entropy Vulnerability” before trying to convince them to give up their wallet backups.
Read more: Trezor says mailing breach leaked 67K more users than first thought
Brevo is also the email provider for crypto firms BitBox, CoinTracking, Peach Bitcoin, and Blocktrainer, all of which have warned users to be wary of phishing emails.
CoinTracking phishing attempts used a fabricated breach to try and trick users, while BitBox phishing attempts warned of a microcontroller entropy bug.
Bad summer to be a Trezor partner
In August, Trezor revealed that its third-party shipping partner ShipMonk was breached, causing the details of 13,689 Trezor customers to be leaked.
The company then revealed a month later that ShipMonk’s leak actually impacted over 80,000 customers.
Trezor was also informed that ShipMonk hadn’t been sticking to a 90-day data deletion policy as promised.
Protos has reached out to Trezor for comment and will update this piece should we hear anything back.
Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.
The post Trezor’s summer of hacks continues with Brevo email breach appeared first on Protos.







