top of page

🚨 Trusted Email Hijacked: Trezor Users Hit by Recovery-Seed Phishing After Brevo Breach

Writer: AigiShield
AigiShield
Sep 12
3 min read

Report date: September 12, 2026

Scam type: Supply-chain phishing / cryptocurrency wallet recovery-seed theft

Source classification: Verified Emerging Scam Alert


What happened

A large phishing campaign reached cryptocurrency users after attackers compromised accounts at Brevo, a third-party email marketing provider. Trezor says a fraudulent security alert was sent through its legitimate newsletter account to roughly 347,000 subscribers. Because the message was sent through real company email infrastructure, it could look far more convincing than a typical spoofed phishing message.

Trezor reported that the malicious message used the subject “Critical Security Alert: STM32 Entropy Vulnerability.” The email linked to a fraudulent application that asked users to enter their wallet backup, also known as a recovery seed. Trezor says about 2,500 recipients clicked the malicious link before the domain was taken down.


How the scam works

The danger is the trusted delivery channel. Instead of merely forging a company name or sender address, the attacker abused a compromised marketing platform to send phishing through legitimate customer accounts. That can defeat one of the most common consumer safety checks: looking at whether the email appears to come from the real company.

The lure then creates urgency around a supposed hardware or security problem and directs the user to a malicious site or application. For cryptocurrency wallet users, the critical goal is to steal the recovery seed. Anyone who possesses that seed can potentially take control of the wallet and move the funds.


Who is being targeted

The confirmed incident affected Trezor newsletter subscribers, but Malwarebytes reports that the Brevo incident also exposed customers of other cryptocurrency-related companies, including CoinTracking and BitBox. Brevo said multiple customer accounts were accessed, and some were used to send phishing emails or export contact lists. Consumers who receive security alerts from cryptocurrency services should be especially cautious, even when the sender address looks legitimate.


Warning signs

• An unexpected “critical security” or vulnerability warning that demands immediate action.

• A request to enter a cryptocurrency wallet recovery seed, backup phrase, or private key.

• A message urging you to install software from a link in the email.

• Pressure to act before independently checking the company's official website or app.

• A message that appears authentic but asks for information the legitimate company says it will never request.


What consumers should do

Do not click security-update links in unexpected cryptocurrency emails. Open the company's known official app or type its website address yourself and check for an alert there.

Never enter a wallet recovery seed or backup phrase into a website or application reached through an unsolicited email. Trezor states that it does not hold wallet backups and will never ask users for one.

If you entered a recovery seed into the fraudulent application, Trezor advises moving funds immediately to a new wallet with a new recovery seed. Also remain alert for follow-up phishing because exposed email addresses may be reused in future attacks.


Why this development matters

This campaign is important because it weakens a familiar rule consumers have been taught to use: “check the sender.” A compromised third-party email platform can allow a scam to arrive through legitimate company infrastructure. That means consumers increasingly need to verify the requested action itself, not just the apparent source of the message.

For high-value accounts, financial services, and cryptocurrency wallets, a legitimate-looking sender is not enough. Independently open the service you trust and confirm the warning there before clicking, installing, approving, or entering sensitive information.


Sources


Think it might be a scam? Let AigiShield check it out for you.

Think Before You Click. Verify Before You Trust.

 
 
 

Recent Posts

See All

Comments


bottom of page