SECURITY Signal 56
Phishing campaign reportedly exploits compromised newsletter provider to target Trezor and BitBox users
Attackers used a breached third-party email service to send fake security alerts demanding crypto wallet backups from Trezor and BitBox users.
This incident highlights the risks of supply-chain attacks in security-critical systems. Even legitimate communication channels can become vectors for phishing if compromised, undermining trust in hardware wallet providers and their partners.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Trezor and BitBox users received phishing emails via a compromised newsletter provider, bypassing authentication checks.
The emails falsely claimed hardware vulnerabilities to trick users into sharing wallet backups.
Both companies confirmed the breach but did not name the provider, though privacy policies point to Brevo.
THE READ
What the cluster adds up to.
A phishing campaign targeted users of Trezor and BitBox hardware wallets by exploiting a compromised third-party email service. The attackers sent emails from legitimate domains, such as `[email protected]`, which allowed the messages to bypass standard spam filters. This demonstrates how supply-chain vulnerabilities can undermine even well-secured systems, as the attack leveraged a trusted communication channel rather than directly breaching the wallet providers themselves.
The phishing emails used a consistent lure, warning users of a fabricated hardware vulnerability affecting entropy in their devices. Trezor’s emails cited an “STM32 Entropy Vulnerability,” while BitBox’s referenced a “Microcontroller Entropy Bug.” Both claimed that wallet seeds were at risk of brute-force attacks due to insufficient randomness. The emails urged recipients to share their wallet backups, a request both companies explicitly warned users to ignore. The uniformity of the scam suggests a broad, opportunistic campaign rather than highly targeted attacks.
Neither Trezor nor BitBox publicly named the compromised provider, but their privacy policies identify Brevo (formerly Sendinblue) as a newsletter service. CoinTracking, another affected company, directly attributed the breach to Brevo. The lack of public confirmation from Brevo leaves uncertainty about the scope of the compromise, though the simultaneous targeting of multiple crypto-related companies suggests a shared vulnerability. This incident underscores the need for hardware wallet providers to audit third-party services and implement additional safeguards for critical communications.
The attack follows a recent data breach at Trezor’s logistics partner, ShipMonk, which exposed the personal details of 80,000 customers. While unrelated, the two incidents compound reputational damage for a company whose brand relies on security. For engineers, this serves as a reminder that security is only as strong as the weakest link in the supply chain. Even if a hardware wallet itself is secure, vulnerabilities in ancillary services, like email providers or logistics partners, can still put users at risk.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER