The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Who Does Trezor Trust With Your Email?

The Perimeter Desk
2026-09-12
# Who Does Trezor Trust With Your Email? Trezor sells peace of mind in a plastic shell. The pitch is simple. Your private keys stay on the device, which keeps your money safe from the internet's mess; it's a clean story about isolation. Only the keys were isolated. The customers weren't. The breach hit over 340,000 crypto users, and no one cracked a seed phrase or found a hardware backdoor. Instead, Trezor trusted Brevo with their customer outreach, and bitBox and CoinTracking did the same. Attackers used a SAML SSO flaw in Brevo to hijack the channel, and why break into Trezor when you can just pretend to be them from the house they rent for mailing lists? The result was 347,000 users receiving phishing emails that looked, smelled, and felt authentic because they were sent through the actual infrastructure used by their service provider. Look at how they're talking about this and you'll see the pattern; first, it was all technical talk about "a data breach of our email provider. They're distancing themselves. By making Brevo the villain and Trezor just a bystander, they try to keep that image of an invincible hardware wallet alive. They want you to think the security part of their business is still fine. Security isn't some plug-in you only use for private keys. It's the whole chain. If you sell to people who are hyper-paranoid, you take on the risks those people have. You can't call yourself the gold standard for custody while outsourcing your customer relations to a third party with an SSO that lets this happen. Why do it? Convenience. Running a secure, internal system for hundreds of thousands of users is a pain and it costs money; brevo is easy because it gives you automation, templates, and analytics. The execs picked the efficiency of a marketing stack over actual security rigor. They traded some operational friction for huge systemic risk, and they didn't tell users their data was in a SAML-vulnerable bucket. Then there is the price. A phishing attack on 347,000 people in crypto isn't just annoying; it's a harvest. We don't know how many wallets are gone yet, but this was the fourth most targeted sector this week, so demand for these assets is high. The real loss isn't the Bitcoin. It's the death of the "cold storage" myth. This is a warning to any vendor claiming they're "security first. If you use the same marketing tools as everyone else, you share the same breaking point, and bitBox and CoinTracking got caught in this too because they used the same provider. We have a new supply chain risk now. I call it "Growth Stack" vulnerability. Attackers know they don't have to hit the hardened target if they can just pivot through the Mailchimps, HubSpots, or Brevos of the world. Some people will say Trezor isn't responsible for a zero-day or some vendor's SSO flaw. They think it's unfair to expect every single partner in a company's ecosystem to be as secure as the main product. That doesn't work here because of what they sell. You don't sell a vault lock and then leave the key under the mat, only to blame the mat maker when someone gets in. By picking Brevo, Trezor decided their marketing efficiency mattered more than the integrity of how they talk to users, and they took a gamble for 347,000 people who thought they bought a fortress. The response was just telling users to "be careful" and ignore weird emails. That's an insult. Telling a user to watch out for phishing from your own verified address is like telling someone to watch for rain while you're the one holding the hose. This wasn't a technical failure, and it was a failure of incentive and imagination. The security team probably knew SaaS tools were risky, but marketing wanted their KPIs and execs wanted growth numbers; when "security" as a product clashed with "growth" as a goal, growth won. It always does, until your reputation is gone. Which leads to the question the PR people hope we ignore: If you gambled with user data for a better newsletter, what other "conveniences" are hiding in your system? Now 347,000 users have to wonder if their wallet actually protects them or if it's just expensive plastic that comes with targeted phishing. The keys might be safe on the chip, but the people holding those keys are exposed.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. GitLab Vulnerability Exploited One Day After Disclosure SecurityWeek
  2. GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure The Hacker News
  3. Trezor Data Breach Exposes Hundreds of Thousands of Crypto Users to Scammers - Yahoo Tech Google News Security
  4. BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days SecurityWeek
  5. In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review SecurityWeek
  6. Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack SecurityWeek
  7. Millions of driver’s license records at risk in data breach. What now? - USA Today Google News Security
  8. Florida DMV says it was hacked shortly after major driver’s license breach - NBC News Google News Security

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.