← BACK TO FEED
phishingcrypto securitysupply chain breachTrezorSSO vulnerability

Trezor Customers Hit by Phishing Wave After Marketing Platform Botches SSO Security

Trezor has warned approximately 347,000 customers that they received phishing emails after its third-party marketing platform, Brevo, was hacked via a SAML Single Sign-On (SSO) vulnerability that allowed an attacker to gain unauthorized access to multiple accounts. The phishing emails, titled "Critical Security Alert: STM32 Entropy Vulnerability," directed users to a malicious website where entering their wallet backup could result in lost funds; around 2,500 users clicked the link before the site was taken down within 20 minutes. This breach follows a separate recent incident in which Trezor's shipping provider ShipMonk exposed the personal data of tens of thousands of customers, raising concerns about an increased risk of targeted phishing attacks against Trezor users.

Trezor is having a rough few weeks. The cold wallet maker has confirmed that around 347,000 of its customers were targeted with phishing emails after attackers got into Brevo, the third-party email marketing platform Trezor uses for newsletters.

The root cause was a fairly ugly SSO implementation flaw. The attacker created their own Brevo account, enabled SAML Single Sign-On, then invited legitimate Brevo users into that configuration. Using their own identity provider, they could authenticate as those invited users. So far, so exploitable. The real problem was that this access wasn't properly scoped to the attacker's own organisation. Instead, it handed them the keys to every organisation those users had access to. That's a serious architectural mistake.

Brevo says the attacker sent phishing messages via six of the compromised accounts and exfiltrated contact lists from 43 others. Trezor's account was among those abused for the phishing campaign.

The emails landed with the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and pointed recipients toward a malicious website. Trezor warned that anyone who clicked through and entered their wallet backup seed phrase would be at risk of losing their funds entirely. Trezor hasn't elaborated on what the site actually did, but the intent is obvious.

About 2,500 users clicked the link before the site was pulled offline, reportedly around 20 minutes after the attack was detected. How many of those users lost anything, and how much, remains unclear.

Trezor isn't alone. BitBox and CoinTracking both appear to have been caught up in the same Brevo breach, though neither has confirmed Brevo as the source or offered much detail on the damage.

The timing is particularly grim for Trezor. This comes less than a month after the company disclosed a separate breach at ShipMonk, a third-party fulfilment provider. Personal data for roughly 14,000 users was initially reported compromised, but a September 4 update expanded that figure to an additional 67,000 US customers, with names, email addresses, shipping addresses, phone numbers, and order numbers all exposed.

Two supply chain breaches in under a month. Trezor's hardware may be solid, but its vendor security posture is looking considerably less watertight.

WATCH THE SHORT
READ NEXT
Drainer-as-a-Service: How Crypto Wallet Theft Became a Subscription BusinessFake Passkeys and CEO Impersonation: Microsoft Exposes Two Nasty Cloud Attack CampaignsClickFix Is Everywhere Now, and It's Not Going Away