Trezor warns of phishing wave after third-party email vendor breach

Hardware wallet maker Trezor disclosed that a cyberattack on its email marketing provider Brevo allowed hackers to send roughly 347,000 phishing emails to customers. The malicious link prompted users to enter their wallet backup password, which could lead to irreversible theft of funds. This is the second breach affecting Trezor's third-party vendors in recent months, following an earlier incident involving shipping partner ShipMonk.
The attack exploited a flaw in Brevo's permission settings, enabling unauthorized access to 138 accounts. The fraudulent emails referenced a specific hardware vulnerability and directed recipients to a malicious app designed to capture their wallet recovery phrase, which would grant full control over their cryptocurrency.
This marks the second vendor-related incident for Trezor, following a ShipMonk breach that exposed personal details of over 81,000 customers. That leaked information has already spawned physical mail scams with QR codes, and could enable criminals to target wealthy individuals for physical coercion to obtain their passwords.
This recurring pattern of third-party breaches could significantly undermine trust in hardware wallets, as users may question whether their personal data is truly secure. Affected customers face the immediate risk of irreversible financial theft if they fall for the phishing app, while the leaked shipping data may expose them to physical coercion or targeted home invasions. The incident underscores the broader challenge of securing complex supply chains in the crypto ecosystem.