Trezor phishing emails came from Trezor's own sending address

About 347,000 people on Trezor's newsletter list received an email on Sept. 9. It warned of an "STM32 Entropy Vulnerability" in their hardware wallet. The sender was mailing@trezor.io. That address is real, the signature checked out, and the message used the same infrastructure Trezor relies on for its own newsletter. Criminals wrote it.
The email claimed that roughly one in four Trezor devices shipped with a factory defect. The random number generator was too weak, it said, and recovery seeds could be brute-forced at 40-bit entropy. Anyone who followed the link reached an app that asked for those recovery words. That is enough to drain a wallet, permanently and with no way to reverse it. Trezor says it pulled the domain at the DNS level within 20 minutes. By then 2,500 recipients had opened the link.
Why checking the sender address does not help here
Trezor sends its newsletter through Brevo, formerly Sendinblue. Brevo's write-up on the incident lays out how the attacker got in. He created his own Brevo account, switched on single sign-on, and invited legitimate Brevo users into that configuration. He could then use his own identity provider to sign in as those users, which on its own is how SSO is meant to work. The failure was in the boundary. Brevo writes that the access "was not properly scoped," so instead of staying inside the one organization it reached every organization those invited users could get to.
Brevo counts 138 affected customer accounts. 6 of them were used to send phishing mail to the contacts stored there, the attacker exported the contact lists from 43, and 93 saw no meaningful activity. Brevo closed the route at 8:30 a.m. UTC on Sept. 10 and signed out every user on the platform. The company says it failed to protect the audiences its customers had entrusted to it. Attacks that come from a real, trusted channel are not unusual. A paid Bing ad for a fake Claude app sent its victims to the genuine vendor page in July.
Trezor was not the only target
Two other companies were caught in the same breach at almost the same time. Swiss hardware wallet maker BitBox reported a near-identical mail to its newsletter subscribers. There the subject line warned about an invented entropy bug in the microcontroller. CoinTracking, a tax and portfolio platform, got a different lure because it sells no hardware. That mail told customers to refresh API keys that were supposedly compromised.
Brevo is neither a niche provider nor a crypto-only story. The French company bought Berlin-based Newsletter2Go along with its customer base in 2019, and a large number of European newsletters use the platform today. You do not need to own a hardware wallet to be on a mailing list hosted by the same provider.
What actually helps here
The standard advice to check the sender address fails in this case, because the address was correct. SPF, DKIM and DMARC raised no flag either. Brevo puts it plainly and writes that the messages "were sent through legitimate infrastructure, so they passed the usual email authentication checks and looked genuine." What is left is the request itself. Trezor states in its post that it "will never contact you asking for your wallet backup." Whoever asks for it is therefore not the vendor. The same rule covers banks, mail providers and any account with recovery codes.
Clicking the link without entering anything leaves you safe, according to Trezor. Anyone who typed in their recovery words should move the funds to a new wallet immediately. The addresses are also likely to stay in circulation. Trezor had to confirm in early September that a breach at its logistics partner ShipMonk affects more than 80,000 customers, far more than it first reported.





