Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

Hardware crypto wallet maker Trezor has warned customers of a second data breach in two months, this time involving a third-party marketing provider. Hackers used the compromised account to send 347,000 phishing emails designed to steal wallet backup passwords.
Why it matters
This incident highlights the significant security risks posed by third-party vendor dependencies and the increasing sophistication of phishing attacks targeting high-value crypto assets.
Hardware crypto wallet maker Trezor is warning customers for the second time in as many months that one of the companies it relies on was hacked, exposing the data of Trezor’s customers to hackers.
In a blog post this week , the hardware wallet maker said a cyberattack on Brevo, a marketing tech company that Trezor uses to send newsletters, allowed hackers to send around 347,000 phishing emails to Trezor customers with a malicious link purporting to come from the wallet maker.
The link, when tapped, downloads an app that asks the victim for their wallet backup password. According to Trezor, one of the email subject lines said: “Critical Security Alert: STM32 Entropy Vulnerability.”
With a stolen wallet password, a hacker can irreversibly steal the person’s funds on the public blockchain.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in