Trezor customers phished after email provider breach

Published

Trezor warned roughly 347,000 newsletter subscribers this week that a security incident at one of its suppliers had turned into a mass phishing campaign aimed at them. The supplier was Brevo, an email marketing platform used by a number of cryptocurrency companies, and the phishing mail went out through Brevo's own infrastructure, from sending domains those customers already trusted.

That is the part that is hard to shrug off. The messages were not spoofed. They came from the real company.

A login shortcut the attacker walked through

Brevo first said an attacker had reached 120 customer accounts. Its postmortem put the figure higher. "On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts," the company wrote. SAML SSO is the single sign-on mechanism that lets an organization log its staff into a service such as Brevo using its own identity provider, so a flaw in how that is handled is a flaw in the front door.

Of those 138 accounts, Brevo says 6 were used to send phishing emails to the contact lists stored in them, 43 had their contacts exported, and 93 showed no meaningful activity. The exported contacts matter as much as the mail that already went out, because they are a ready-made target list for whoever holds them next.

A fake chip defect, and a box for your seed

Trezor, CoinTracking and BitBox all confirmed that phishing emails reached subscribers on their newsletter lists, and Malwarebytes Labs collected the lures alongside Brevo's statement. The message sent to Trezor customers carried the subject line "Critical Security Alert: STM32 Entropy Bug Identified" and the subtitle "Urgent update regarding hardware microcontroller vulnerability." It claimed the company's engineers had found a hardware factory defect in an estimated 1 in 4 devices, mostly those initialized before 2023, leaving recovery phrases with as little as 40 bits of entropy and therefore open to brute-force cracking.

None of that is real, but it is well built. It invents a problem only a hardware wallet owner would find frightening, then offers the one action that would actually hand over the money: the email linked to an app download and a field asking for the wallet backup. A recovery phrase typed anywhere other than the device itself is a recovery phrase in somebody else's hands. CoinTracking subscribers got a different pitch of the same shape, an email titled "Data Breach Notice: Please refresh API Keys as soon as possible," also carrying a malicious link.

Trezor owners have been singled out by impersonation lures before, including a campaign that killed the real wallet app and put a fake one in its place. What is different here is the delivery. The attacker did not have to imitate a trusted sender, because the attacker was using one, and that is the same leverage behind phishing kits that ride genuine Docusign notifications.

If you typed your recovery phrase, move the funds

Trezor's advice to anyone who entered a wallet backup in any form is to move the funds to a new wallet, and that is the right call: a seed that has been typed into a web page cannot be made safe again. CoinTracking users who followed the link should rotate their API keys. For everyone else sitting on a newsletter list, the durable rule is that an urgent security email is a reason to open the company's own site or app and check there, never to click what you were sent. Reputable companies do not ask for recovery phrases, API keys or logins by email, whatever domain the message arrives from.

How many people fell for it is not known. What is known is that 43 contact lists left the building, so the next wave already has somewhere to go.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions