Trezor Data Breach Exposes Hundreds of Thousands of Crypto Users to Scammers

Brevo authorization flaw let attackers hijack Trezor’s mailing list, while a ShipMonk SQL breach exposed 80,000 customers’ home addresses

Al Landes Avatar
Al Landes Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • Brevo’s authorization flaw let attackers send phishing emails to 347,000 Trezor subscribers directly.
  • A ShipMonk SQL injection breach exposed 80,689 customers to physical “wrench attack” threats.
  • Never enter a wallet backup phrase into any app prompted by an email link.

Roughly 347,000 Trezor newsletter subscribers received an email on September 9, 2026, warning of a critical hardware vulnerability. It looked official. It came from Trezor’s own mailing infrastructure. It was a scam, sent by attackers who never touched a single Trezor device.

That gap between “device secure” and “you’re still at risk” is exactly what makes this incident worth understanding. Even password vaults have fallen to third-party platform exploits, underscoring how no ecosystem is fully insulated from vendor-side risk.

How Attackers Used Trezor’s Own Newsletter Against Its Customers

A flaw in Brevo’s access controls handed attackers the keys to over a hundred client accounts at once.

Brevo, the email marketing platform Trezor uses for newsletters, suffered a breach that exposed roughly 120 to 138 client accounts due to an authorization failure. Access that should have been limited to a single account was, according to Brevo’s published incident notice as reported by TechCrunch, “wrongly granted” across multiple organizations. Attackers exploited that flaw to send phishing emails directly from Trezor’s newsletter infrastructure.

The subject line read: “Critical Security Alert: STM32 Entropy Vulnerability.” The email directed recipients to download an app that then requested their wallet backup phrase, the string of words that unlocks complete access to every crypto asset stored in a wallet. Entering that phrase into the attacker’s app would have meant irreversible loss of funds.

According to Trezor’s post on X, “Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us.” Trezor’s official blog confirmed that clicking the link alone does not compromise a wallet; the danger only materializes if a user enters their backup phrase. Trezor suspended its Brevo account immediately and contacted affected subscribers directly.

From Digital Phishing to Physical Mail and “Wrench Attacks”

A separate breach at shipping partner ShipMonk turned a digital threat into a real-world one.

Before the Brevo incident, Trezor had already disclosed a breach at ShipMonk, its order fulfillment partner. Attackers exploited a SQL injection vulnerability in ShipMonk’s Metabase analytics platform, first disclosed on August 13, 2026. The initial notice covered roughly 13,689 customers. A September 4 update added approximately 67,000 U.S. customers whose data sat in older order archives dating back to November 2019, bringing the combined total to around 80,689 people.

Exposed records included full names, shipping addresses, phone numbers, email addresses, and order numbers. No wallet keys, seed phrases, or Trezor device data were involved in either incident.

That ShipMonk breach is where the threat shifted from your inbox to your front door. Some affected customers received physical letters impersonating Trezor, including QR codes linking to credential-stealing pages designed to capture wallet backup phrases. According to TechCrunch, the combination of exposed home addresses and known crypto ownership puts these individuals at risk of targeted violence. These are so-called wrench attacks: physical coercion used to force victims to hand over seed phrases or passwords. The tactics echo those of a surveillance app built to exploit specific, identifiable groups through digital means.

Knowing someone owns crypto is one thing. Knowing their name, home address, and phone number is another.

What to Do Right Now

Trezor’s guidance is direct; the broader lesson here is structural.

  • Treat any urgent security alert as suspicious until verified through official channels, even one that appears to come from a trusted sender. Reviewing how to stay safe against physical and digital attack vectors is equally important.
  • Never enter a wallet backup phrase into any app or website prompted by an email link.
  • If a seed phrase was entered into any online form or app at any point, move funds to a new wallet immediately.

Trezor says it is reevaluating its vendor relationships in light of both breaches. Hardware wallet security and vendor security are not the same thing. Your device can be airtight while the company that ships it and markets it quietly hands attackers a map to your door.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →