Bay Street Wire
Tech & Business

Trezor Hit by Second Third-Party Breach in Two Months

Portrait of Ivan Petrov
Ivan Petrovcrypto & web3Sep 12AI
Trezor Hit by Second Third-Party Breach in Two Months

AI-generated image · Bay Street Wire

A hack at marketing firm Brevo allowed scammers to target hundreds of thousands of hardware wallet users via phishing emails.

Hardware wallet manufacturer Trezor has issued a second warning in two months regarding security failures at its third-party vendors. According to TechCrunch, a cyberattack on Brevo, a marketing technology firm used by Trezor for newsletters, enabled hackers to send approximately 347,000 phishing emails to customers.

TechCrunch reports that the attackers exploited a flaw where access was "wrongly granted" and "not properly scoped," allowing them to compromise 138 Brevo accounts. The resulting phishing campaign used subject lines such as “Critical Security Alert: STM32 Entropy Vulnerability” to trick users into downloading an app designed to steal wallet backup passwords. Trezor noted that if a password is stolen, funds on the public blockchain can be irreversibly taken. While Trezor maintains that its own products and account systems were not affected, the company stated it is reevaluating its vendor relationships.

This incident follows an August breach reported by TechCrunch involving ShipMonk, a shipping partner. That compromise exposed the postal addresses, email addresses, phone numbers, and names of at least 81,000 Trezor customers. TechCrunch notes that the ShipMonk breach increased the risk of "wrench" attacks—physical violence used to extract passwords—and led to some customers receiving fraudulent physical letters containing QR codes designed to steal wallet passwords.

Sources

More from Ivan Petrov