Trezor, BitBox users targeted in newsletter phishing spree
Trezor has warned customers that a third-party email provider used for its newsletters was breached, resulting in phishing messages being sent to subscribers under the guise of the genuine "mailing@trezor.io" address. The emails falsely claim a "hardware factory defect" leaves wallet seeds vulnerable due to insufficient entropy, and urge recipients to submit their wallet backups, a request Trezor insists customers should never fulfil. The issue is notable because the messages pass authentication checks, making them harder to filter than typical phishing attempts, though their generic, non-personalised wording makes them relatively easy to spot.
Swiss rival BitBox reported a near-identical campaign targeting its own newsletter subscribers, and crypto tax firm CoinTracking disclosed a similar breach around the same time, using a different lure about API key refreshes. Neither Trezor nor BitBox named the compromised provider, but both companies' privacy policies point to Brevo (formerly Sendinblue), which CoinTracking explicitly confirmed as its provider; Brevo has not commented. The news follows Trezor's disclosure last month of a separate breach at logistics partner ShipMonk, which has now grown from an initial estimate of 13,000 affected customers to 80,000, exposing names, email addresses, phone numbers and shipping addresses.
- Trezor and BitBox newsletter provider breached, enabling authentic-looking phishing emails
- Emails falsely claim entropy flaws and ask users to submit wallet backups
- Brevo suspected as shared provider; separate Trezor ShipMonk breach now hits 80,000 users