Securitize Broadens Blockchain Network With UAE’s ADI Chain
Trump Unveils 'Morally Binding' AI Accord Signed by OpenAI, Google and Nvidia
1,824 $BTC (153,770,122 USD) transferred from unknown wallet to unknown wallet...
USDai and sUSDai Expand to Solana; Cumulative Cross-Chain Transfer Volume via LayerZero Exceeds $2 Billion
Brazilian State Energy Giant Petrobras Taps Cardano for Tracing Fuel
Coinbase, Visa, and Others Become Founding Partners of Open Standard
Short-term Bitcoin Buyers Report 13% Profit as Market Stabilizes
OpenUSD - Backed By Coinbase, Mastercard, Shopify, Stripe, And Visa - Went Live On Wednesday,...
SEC proposes easing private investment thresholds to push retail investors into private markets
Australia’s Crypto Grace Period Just Ran Out
AllUnity Launches a Dollar Stablecoin Built for Europe
FCA Opens Five-Month Authorisation Window for UK Crypto Firms
Robinhood Chain kept producing blocks through a roughly 40-minute app disruption
Bitcoin Jumps on Cool PCE Inflation Data as Bond Yields Hit 20-Year Highs
Hyperliquid Labs will unstake $320M in hyperliquid:native today for its...
Hyperliquid Labs Will Unstake $320M Of $HYPE Today For Its Monthly Team Unlock, Will Be Sold OTC To...
Ethereum Options Open Interest Represents 23% of Futures Market
Stripe Adopts Open USD as Default Stablecoin for Business Transactions
Mt. Gox Holds Nearly $3 Billion in Bitcoin Ahead of Final Repayment Deadline
Open USD takes on Tether, Circle with a different stablecoin model that's 'building money'
CFTC Proposes Rules to Regulate Event Contracts as Swaps
Launch of OUSD Stablecoin by Open Standard and Bridge Under Stripe
Total crypto liquidations hit $277 million in past 24 hours, longs and shorts both wiped out
Open Standard, backed by 140+ firms including Stripe, Visa and...
Hyperliquid Labs to unstake ~$320 million in HYPE and sell to an institution via OTC
IDEX Crypto Explained: How the Hybrid DEX Works, Token…
Strategy’s Saylor Sees Separate Capital Pools for Bitcoin Treasury Firms
How to Block Cryptojacking: Browser Extensions That Stop…
‘Fake News’: El Salvador Denies Stablecoin Pivot as Bitcoin Treasury Grows
Tempo Launches Open USD Integration for Enhanced Enterprise Payments
Bitcoin Enters Q4 Needing Stronger Spot Demand
U.S. CFTC seeks event contract definitions that may defy states' gambling claims
Ex-NCA Officer Must Repay $2.4M for Bitcoin He Stole When It Was Worth $77K
Ostium to Compensate Users Affected by Wallet Losses
Tokenized Real-World Assets Reach $34.5 Billion, But Trading Activity Remains Low
Swift blockchain ledger now live, at least 19 banks expected to join by year-end
UK FCA Opens Crypto Authorisation Applications Ahead of 2027 Regime
CFTC filed two rulemakings with White House's Office of Information and
US Senate Majority Leader: Congress may raise debt ceiling after midterm elections
AI Voice Company ElevenLabs Doubles Valuation to $22 Billion
OKX Sees Bitcoin Holdings Climb in Its 47th Reserve Check
Trump’s AI name change sparks insider domain trading claims
Strength Meets a Wall
Devcon 8 Scheduled for Mumbai from November 3-6, 2026
Ostium Recovery Plan Completes Full Repayment for Majority of Affected Wallets
Goldman Sachs expects U.S. pension funds to sell about $33 billion in...
Coinbase CEO: Building financial accounts for AI "superintelligence," covering trading, payments and lending
Sumitomo Mitsui Trust Bank acquires all shares of JADAT, making it a wholly owned subsidiary
Robinhood Bets on AI Agents and 10x Crypto Perps to Win Active Traders
Crypto Long & Short: What will the AI agents run on?
Wells Fargo, Bank Of America Raise AMD Stock Price Target
Chainlink Launches Fulcrum to Connect Repo Finance Across Blockchains
SEC changes token buyback guidance as spending hits $638M
Crypto Escrow APIs Explained: How Fiat Conversion Works in…
Robinhood CEO Vlad Tenev went into more detail on company’s AI trading agents and
FCA Sets February 2027 Deadline for Crypto Firms Seeking UK…
CoinShares: Digital Asset Investment Products See $3.55B in Weekly Inflows, Largest This...
FCA Opens UK Crypto Gates More Than a Year Before Rules Hit
Drift Foundation Freezes $9.2 Million in Stolen Funds Amid Ongoing Recovery Efforts
Morpho Launches Offer-Based Markets for Onchain Credit with New Protocol
Coinbase Launches Financial Accounts for AI Agents
MSTR Stock Outperforms Bitcoin in September, Price Jumps 16%
White House: Trump to Announce South Korea's $200 Billion U.S. Energy Investment Plan
Muneeb Ali Appointed CEO of Stacks Labs as Bitcoin Staking Gains Traction
Bilibili open-sources Index-Translate translation model, supporting 150 languages
Drift: About $9.2 million of the stolen $295.4 million has been frozen, recovery still pending
Bitcoin Price Breaks $85K as Softer U.S. PCE Inflation Eases Rate-Hike Fears
TheDAO Security Fund launches second round, $600,000 to fund Vyper compiler
Soneium Adopts OP Enterprise Fully Managed Service, Optimism to Provide Chain Operation Support
Trezor Reported a Breach at a Third-party Email Provider Amid a Phishing Attack
- Attackers used Trezor’s mailing infrastructure to distribute phishing emails.
- BitBox and CoinTracking faced similar attacks.
- Independent researchers link the incidents to Brevo’s infrastructure, but there is no official confirmation from the provider as of the time of writing.
On September 9, 2026, hardware wallet maker Trezor reported that a third-party email provider had been compromised. Attackers sent emails posing as the company with the subject line “Critical Security Alert: STM32 Entropy Vulnerability,” claiming there was a critical vulnerability in the hardware wallets.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
— Trezor (@Trezor) September 9, 2026
We have taken down the domain, and we are investigating…
Trezor stressed that the message is not related to the company and is a phishing attempt. The team took down the domain used in the attack and launched an investigation, including into how the attackers gained access to the mailing infrastructure. The company did not disclose the name of the third-party provider.
According to recipients, the malicious emails looked especially convincing because they came from help@trezor.io, and the headers referenced the domain mailing.trezor.io.
The messages also passed standard SPF, DKIM, and DMARC checks. As a result, the mailing could appear authentic to the email service despite the fraudulent content.
The email claimed that a flaw in STM32 microcontrollers could allegedly reduce the reliability of generated seed phrases. Recipients were urged to follow a link and check their device. On the phishing pages, attackers could request an xPub or even the recovery phrase.
Incrypted’s editorial team reached out to Trezor for comment regarding the incident. We will update the article when and if we receive a response.
Trezor Not the Only Victim of Attackers
Hardware wallet maker BitBox confirmed the distribution of phishing emails and later published the results of a preliminary review. According to the team, the email distribution service provider was very likely compromised.
BitBox also said that several other crypto companies were targeted as well, and they likely used the same provider.
In BitBox’s case, attackers sent an email with the subject line “Critical Security Alert: Microcontroller Entropy Bug Identified.” The company warned subscribers, contacted the service provider, and reported the phishing domains. At the time the statement was published, most of the malicious links had already been taken down.
Another publicly identified target was crypto portfolio tracking platform CoinTracking. Users received emails from support@cointracking.info with the subject line “Data Breach Notice: Please refresh API Keys as soon as possible.” The messages attempted to persuade potential victims to refresh their API keys via a third-party resource.
CoinTracking also posted a warning about phishing emails circulating. The company noted that the fraudulent messages lead to websites requesting credentials for access to crypto exchanges, and emphasized that the service’s staff never ask for login details or API keys with trading and withdrawal permissions.
As a result, at the time of writing, at least three brands are publicly known to have been impersonated in similar messages: Trezor, BitBox, and CoinTracking.
A likely common link may be the email marketing platform Brevo, previously known as Sendinblue. Researchers found a shared DKIM configuration across the Trezor and BitBox domains, and industry sources reported the creation of unauthorized API keys in affected Brevo accounts.
However, neither Trezor nor BitBox named the provider in their initial statements, so it is still premature to talk about a confirmed breach of Brevo’s core infrastructure.
The initial attack vector also remains unclear. It could have been an incident on the service’s side, or attackers gaining access to individual client accounts and then creating API keys. As of writing, no public statement from Brevo that would definitively clarify this issue could be found.
Notably, a similar scheme was already used against Trezor customers in August 2026. At the time, attackers also sent out warnings about an allegedly critical vulnerability related to entropy and seed phrase generation.
Trezor said at the time that attackers could have combined information from various data leaks at cryptocurrency services. This incident is different, however, in that the phishing messages, based on the available data, were distributed via legitimate email marketing infrastructure.
At this point, there is no confirmation that the vulnerability described in the emails actually exists in Trezor or BitBox devices. The companies recommend that users do not click links in suspicious emails and, under no circumstances, enter their recovery phrase on websites.
Сообщение Trezor Reported a Breach at a Third-party Email Provider Amid a Phishing Attack появились сначала на INCRYPTED.
Source: Incrypted