Trezor, a hardware cryptocurrency wallet manufacturer, has issued a warning to its customers after a data breach at Brevo, an email marketing company it uses. The breach allowed hackers to send approximately 347,000 phishing emails to Trezor users. These emails contained malicious links that, if clicked, prompted recipients to download an app requesting their wallet backup passwords. Such information can enable attackers to steal cryptocurrency funds irreversibly on the blockchain.
Brevo reported that hackers exploited a vulnerability granting unauthorized access to 138 of its customer accounts, enabling them to send phishing messages across multiple organizations. The company acknowledged that the access permissions were improperly configured, allowing the attackers broader reach than intended.
Trezor emphasized that its own products, wallets, and account systems were not compromised in this incident. However, this breach follows a recent security issue involving Trezor's shipping partner ShipMonk, where personal information of at least 81,000 customers was exposed. That earlier breach has already led to targeted phishing attempts, including fraudulent mailings with QR codes designed to steal wallet credentials.
These incidents highlight the risks posed by third-party service providers in the cryptocurrency ecosystem. Compromised customer data can lead to sophisticated phishing campaigns and physical threats such as "wrench" attacks, where criminals attempt to coerce victims into revealing passwords.
In response, Trezor is reviewing its vendor relationships and advising customers to remain vigilant against potential phishing attempts using their email addresses. The company’s warnings underscore the importance of securing personal data and maintaining caution when interacting with unsolicited communications.