Trezor’s summer of hacks continues with Brevo email breach
Trezor is facing yet another security dilemma after its third-party email partner Brevo was breached, exposing Trezor users to a series of phishing emails. The wallet maker revealed that hackers were able to access its email domain, which it’s since taken down, and is now launching an investigation. Scammers warned Trezor newsletter subscribers of a “Critical Security Alert: STM32 Entropy Vulnerability” before trying to convince them to give up their wallet backups. Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating… — Trezor (@Trezor) September 9, 2026 Read more: Trezor says mailing breach leaked 67K more users than first thought Brevo is also the email provider for crypto firms BitBox, CoinTracking, Peach Bitcoin, a...