US National WireUS NATIONAL WIRE
Tech

Hardware Wallet Users Targeted in Brevo Email Breach

Portrait of Nate Okafor
Nate Okaforcrypto & web3Sep 11AI
Hardware Wallet Users Targeted in Brevo Email Breach

AI-generated image · US National Wire

Phishing campaigns targeting Trezor and BitBox customers exploit a compromised third-party mailing service to solicit seed phrases.

As first reported by The Register, a security breach at third-party email service provider Brevo (formerly Sendinblue) has enabled attackers to launch phishing campaigns against users of several cryptocurrency companies, including hardware wallet makers Trezor and BitBox, as well as portfolio-tracking firm CoinTracking.

According to reporting from The Register, Brevo confirmed a security incident that allowed an attacker to access 120 accounts, which were then used to send phishing emails to the clients' contact bases.

Users of Trezor and BitBox received nearly identical emails warning of hardware vulnerabilities. Trezor customers were sent messages titled "Critical Security Alert: STM32 Entropy Vulnerability," which claimed a "hardware factory defect" affected roughly one in four devices. The emails alleged that "insufficient randomness" and "critically low 40-bit entropy" left wallet seeds vulnerable to brute-force attacks, ultimately prompting users to share their wallet backups. BitBox users received a similar warning titled "Critical Security Alert: Microcontroller Entropy Bug Identified."

Because the attackers compromised the legitimate email provider, The Register reports that the messages—sent from "mailing@trezor.io" in the case of Trezor—could bypass standard authentication checks used by email services.

Trezor warned customers via social media and its Trezor Suite app to never enter wallet backups anywhere and to physically confirm every action with the device. BitBox confirmed on X that it is investigating the situation and has reported the phishing domains, noting that most links have already been removed.

CoinTracking also reported the Brevo compromise. Because the company does not sell hardware wallets, the phishing lure used for its customers differed, asking users to follow a link to refresh their API keys.

This incident follows a separate security failure for Trezor. The Register reports that Trezor recently disclosed a breach at its logistics partner, ShipMonk. While Trezor initially estimated 13,000 customers were affected, the company confirmed on September 4 that the total rose to 80,000. This included those who ordered between May 10 and August 8, and 67,000 U.S. customers who bought products from November 2019 through August 2021. The breached data included phone numbers, email addresses, names, and shipping addresses. Trezor stated it was disappointed to find the data had not been deleted by ShipMonk despite written assurances.

Sources

More from Nate Okafor