Trezor Reports Third-Party Email Provider Breach Amid Phishing Attack

5 Min Read Tags:
  • Trezor said on Sept. 9, 2026, that attackers used a compromised third-party email provider to distribute phishing messages impersonating the hardware wallet maker.
  • BitBox and CoinTracking reported similar phishing campaigns, with messages sent through apparently legitimate email infrastructure.
  • Researchers identified possible links to Brevo, but the provider had not publicly confirmed a breach at the time of writing.

Hardware wallet maker Trezor reported on Sept. 9, 2026, that a third-party email provider had been compromised and used to send phishing messages impersonating the company. The incident was significant because the emails came from a Trezor address, referenced its mailing domain and passed standard email-authentication checks.

The messages used the subject line Critical Security Alert: STM32 Entropy Vulnerability and claimed that a critical vulnerability affected Trezor hardware wallets. Trezor said the emails were not from the company, warned recipients not to click any links and said it had taken down the domain used in the attack and opened an investigation.

Trezor did not identify the third-party provider or explain how the attackers obtained access to the mailing infrastructure. Recipients said the emails came from [email protected] and that their headers referenced mailing.trezor.io. The messages also passed SPF, DKIM and DMARC checks, allowing them to appear authentic to email services despite their fraudulent content.

The emails alleged that a flaw in STM32 microcontrollers could reduce the reliability of generated seed phrases and directed recipients to a website to check their devices. The phishing pages could request an xPub or a wallet recovery phrase.

Incrypted contacted Trezor for comment and will update the report if it receives a response.

BitBox and CoinTracking targeted

Hardware wallet maker BitBox also confirmed that phishing emails had been distributed and later published preliminary findings. The company said its email distribution provider had very likely been compromised and that several other cryptocurrency companies using the same provider were probably targeted.

The BitBox emails used the subject line Critical Security Alert: Microcontroller Entropy Bug Identified. BitBox warned subscribers, contacted its service provider and reported the phishing domains. Most of the malicious links had been removed by the time the company published its statement.

Crypto portfolio-tracking platform CoinTracking was another publicly identified target. Users received messages from [email protected] with the subject line Data Breach Notice: Please refresh API Keys as soon as possible. The emails directed recipients to a third-party resource to refresh their API keys.

CoinTracking posted a warning that the fraudulent messages linked to websites seeking credentials for cryptocurrency exchanges. The company said its staff never ask users for login credentials or for API keys carrying trading and withdrawal permissions.

At least three brands — Trezor, BitBox and CoinTracking — were publicly known to have been impersonated in similar campaigns at the time of writing.

Researchers examine possible Brevo link

Researchers identified email marketing platform Brevo, formerly known as Sendinblue, as a possible common link. They found a shared DKIM configuration across the Trezor and BitBox domains, while industry sources reported that unauthorized API keys had been created in affected Brevo accounts.

Neither Trezor nor BitBox named the provider in its initial statement, however, and there was no confirmation that Brevo’s core infrastructure had been breached. The initial attack vector also remained unclear: the incident could have originated on the provider’s side, or attackers could have accessed individual client accounts and created API keys. No public statement from Brevo definitively addressing the issue had been identified at the time of writing.

A similar phishing campaign targeted Trezor customers in August 2026, using warnings about an alleged critical vulnerability involving entropy and seed-phrase generation. Trezor said at the time that attackers could have combined information from data leaks at various cryptocurrency services. The latest incident differed because available information indicated that the phishing messages were distributed through legitimate email marketing infrastructure.

There was no confirmation that the vulnerabilities described in the emails existed in Trezor or BitBox devices. Both companies advised users not to click links in suspicious emails and never to enter a recovery phrase on a website.

Source: Incrypted

Anthropic Models 3 US Economic Scenarios Through 2030

Anthropic published a model outlining three scenarios for the U.S. economy through 2030, with its extreme scenario suggesting annual GDP growth could reach 15% alongside historically high unemployment.

7 Min Read
Robinhood CEO Says Companies Cannot Control Tokenization of Their Shares

In September 2026, Robinhood CEO Vlad Tenev said companies cannot prevent third-party products linked to their shares, defending 1:1 share-backed Stock Tokens after AMC CEO Adam Aron challenged their legality.

5 Min Read
Germany Will Change Crypto-Asset Tax Rules in 2027, Media Reports

Germany’s draft crypto tax reforms would from Jan. 1, 2027, tax profits on covered assets acquired after Dec. 31, 2026, regardless of holding period, while platforms would begin withholding tax…

5 Min Read
Vitalik Buterin Says Recursive STARKs Could Cut Ethereum Private, Post-Quantum Transaction Costs

On Sept. 9, Ethereum co-founder Vitalik Buterin explained EIP-8288, a proposal to aggregate STARK proofs and cryptographic signatures at the mempool level, potentially reducing costs without changing the EVM.

6 Min Read
Bybit Launches AI Assistant for Trading, Account Management

Bybit announced the launch of Bybit AI, a voice assistant that lets eligible users access trading, account management and customer support through one app chat interface after activating an isolated…

4 Min Read