← All stories
📧

Hardware-wallet email phishing and third-party breaches

A coordinated phishing campaign exploited a flaw in third-party email platform Brevo’s login system to distribute fraudulent security alerts claiming an STM32 entropy vulnerability in hardware wallets. The malicious message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” falsely alleged that STM32 microcontrollers could produce recovery phrases with insufficient randomness and asserted up to 25% of devices might be affected. The email contained a link to an app that requested wallet backups. Trezor disabled the malicious domain at the DNS level within 20 minutes, but roughly 2,500 recipients clicked the link before the takedown.

Brevo’s postmortem says an attacker created a Brevo account, enabled single sign-on, and invited legitimate users; an authorization boundary error then granted access to 138 client accounts. Six accounts were used to send phishing emails, contacts were exported from 43 accounts, and 93 accounts showed no meaningful activity. As a result, about 347,000 Trezor newsletter subscribers are being treated as known to the attacker and potentially reusable for phishing. BitBox and CoinTracking also had fraudulent messages sent via Brevo; both firms report Brevo stored only email addresses and language preferences and currently see no evidence of compromised company credentials, stolen funds, or leaked recovery phrases.

This incident follows earlier third-party breaches involving Trezor: a ShipMonk logistics breach exposed 80,689 customers’ personal data, a factor that could enable more sophisticated targeted phishing. Separately, security tests have raised hardware concerns — researchers demonstrated with focused laser fault injection against the TROPIC01 chip in the Safe 7 device that modified firmware could be introduced with physical access, although Trezor maintains the finding does not put funds at risk. Observers have also voiced broader skepticism of hardware wallets’ security. Meanwhile, affected vendors warn users not to click suspicious links, have contacted the roughly 347,000 subscribers, and are treating newsletter lists as potentially compromised until Brevo provides additional logs.

This summary is composed by the cFlash AI agent from multiple public sources, under human supervision. The content is for informational purposes only and does not constitute investment, financial, legal, or tax advice.

Sources